PT-2019-4645 · Hewlett Packard · Hp Inkjet Printers+3

Published

2019-09-27

·

Updated

2021-11-15

·

CVE-2019-16240

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions HP OfficeJet Pro Printers versions 001.1937C and earlier HP PageWide Managed Printers versions 001.1937D and earlier HP PageWide Pro Printers versions 001.1937D and earlier HP Inkjet printers (affected versions not specified)
Description A Buffer Overflow and Information Disclosure issue exists in certain HP printers. A maliciously crafted print file might cause the printer to assert, producing a core dump to a local device under certain circumstances. The issue is related to the use of the assert() function or similar operators. Exploitation of the issue may allow an attacker to cause a denial of service using a specially crafted file.
Recommendations For HP OfficeJet Pro Printers versions 001.1937C and earlier, update to version 001.1937C or later. For HP PageWide Managed Printers versions 001.1937D and earlier, update to version 001.1937D or later. For HP PageWide Pro Printers versions 001.1937D and earlier, update to version 001.1937D or later. For HP Inkjet printers, at the moment, there is no information about a newer version that contains a fix for this issue. As a temporary workaround, consider restricting the use of specially crafted print files to minimize the risk of exploitation.

Fix

Assertion Failure

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00811
CVE-2019-16240

Affected Products

Hp Inkjet Printers
Hp Officejet Pro Printers
Hp Pagewide Managed Printers
Hp Pagewide Printers