PT-2010-2376 · Lexmark · Lexmark Multi-Function Printers+1
Published
2010-03-24
·
Updated
2018-10-10
·
CVE-2010-0619
CVSS v2.0
7.3
High
| Vector | AV:N/AC:H/Au:N/C:C/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Lexmark laser printers and multi-function printers (affected versions not specified)
Description
A stack-based buffer overflow issue exists in certain components of Lexmark printers, including base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE. This issue can be exploited by sending a long argument to a "PJL INQUIRE command" API endpoint, allowing remote attackers to execute arbitrary code or cause a denial of service, resulting in a device hang.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lexmark Laser Printers
Lexmark Multi-Function Printers