IBM Infoprint Printers Remote Management Buffer Overflow Vulnerability
BID:6047
Info
IBM Infoprint Printers Remote Management Buffer Overflow Vulnerability
| Bugtraq ID: | 6047 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2002 12:00AM |
| Updated: | Oct 25 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Toni Lassila" <[email protected]>. |
| Vulnerable: |
IBM Infoprint Controller Software 1.0 47012 |
| Not Vulnerable: |
IBM Infoprint Controller Software 1.0 56007 IBM Infoprint 32 |
Discussion
IBM Infoprint Printers Remote Management Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for IBM Infoprint series of printers.
The vulnerability is present in the Telnet-based remote management services of the printer. It has been reported that when using the remote management services, the printer does not perform adequate checks on user supplied input for the login parameter.
By sending an excessively long string to the printer's remote management services, it is possible to cause the device to be unresponsive to further requests for service.
This vulnerability was reported on IBM Infoprint 21 printers with Controller Software version 1.047012. IBM Infoprint printers with Controller Software version 1.056007 are reportedly not vulnerable to this issue. IBM Infoprint 32 (model 4332-002) printers running printer software version 2.55F and network software version 7.34 are reported to not be affected by this issue.
A buffer overflow vulnerability has been reported for IBM Infoprint series of printers.
The vulnerability is present in the Telnet-based remote management services of the printer. It has been reported that when using the remote management services, the printer does not perform adequate checks on user supplied input for the login parameter.
By sending an excessively long string to the printer's remote management services, it is possible to cause the device to be unresponsive to further requests for service.
This vulnerability was reported on IBM Infoprint 21 printers with Controller Software version 1.047012. IBM Infoprint printers with Controller Software version 1.056007 are reportedly not vulnerable to this issue. IBM Infoprint 32 (model 4332-002) printers running printer software version 2.55F and network software version 7.34 are reported to not be affected by this issue.
Exploit / POC
IBM Infoprint Printers Remote Management Buffer Overflow Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
IBM Infoprint Printers Remote Management Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IBM Infoprint Printers Remote Management Buffer Overflow Vulnerability
References:
References:
- RE: IBM Infoprint Remote Management Simple DoS (update) ("Toni Lassila"
)