HP JetDirect Internal Webserver Long URL DoS Vulnerability
BID:814
Info
HP JetDirect Internal Webserver Long URL DoS Vulnerability
| Bugtraq ID: | 814 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 18 1999 12:00AM |
| Updated: | Nov 18 1999 12:00AM |
| Credit: | Discovered and posted to bugtraq on November 18 by Tobias Haustein <[email protected]>. |
| Vulnerable: |
HP JetDirect J3111A rev. G.05.35 |
| Not Vulnerable: |
HP JetDirect J3111A rev. G.07.17 HP JetDirect J3111A rev. G.07.02 |
Discussion
HP JetDirect Internal Webserver Long URL DoS Vulnerability
The JetDirect J3111A module is used to connect many models of HP printers to a network. It includes a bult-in webserver for remote printer administration. This server is vulnerable due to an overflowable buffer in the code that handles incoming URLs. If a URL longer than 256 characters is requested the printer will crash.
This problem seems to be dependent on firmware revision. If you know of a firmware revision that has been tested with regards to this vulnerability, please email [email protected] .
The JetDirect J3111A module is used to connect many models of HP printers to a network. It includes a bult-in webserver for remote printer administration. This server is vulnerable due to an overflowable buffer in the code that handles incoming URLs. If a URL longer than 256 characters is requested the printer will crash.
This problem seems to be dependent on firmware revision. If you know of a firmware revision that has been tested with regards to this vulnerability, please email [email protected] .
References
HP JetDirect Internal Webserver Long URL DoS Vulnerability
References:
References: