ID

VAR-200602-0089


CVE

CVE-2006-0592


TITLE

Lexmark Printer Sharing LexBce Server Service Unknown vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200602-090

DESCRIPTION

Unspecified vulnerability in the Lexmark Printer Sharing LexBce Server Service (LexPPS), possibly 8.29 and 9.41, allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based on a vague initial disclosure; details will be updated after the grace period has ended. TITLE: Lexmark Printers LexBce Server Arbitrary Code Execution SECUNIA ADVISORY ID: SA18744 VERIFY ADVISORY: http://secunia.com/advisories/18744/ CRITICAL: Moderately critical IMPACT: System access WHERE: >From local network OPERATING SYSTEM: Lexmark X1100 Series http://secunia.com/product/7842/ SOFTWARE: Lexmark LexBce Server (LexPPS) 8.x http://secunia.com/product/7856/ Lexmark LexBce Server (LexPPS) 9.x http://secunia.com/product/7847/ DESCRIPTION: Peter Winter-Smith of NGSSoftware has reported a vulnerability in the LexBce Server Service included with various Lexmark printers, which can be exploited by malicious people to compromise a user's system. This can be exploited to execute arbitrary code on a system with Lexmark printer installed. NOTE: The service is installed with the printer drivers of Lexmark X1100 series (LexPPS version 8.29), and X2200 series (LexPPS version 9.41). Other Lexmark printers may also have the service installed. SOLUTION: Disable the service if printer sharing is not required. PROVIDED AND/OR DISCOVERED BY: Peter Winter-Smith, NGSSoftware. ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 1.08

sources: NVD: CVE-2006-0592 // VULHUB: VHN-16700 // PACKETSTORM: 43675

AFFECTED PRODUCTS

vendor:lexmarkmodel:printer sharingscope:eqversion:8.29

Trust: 1.6

vendor:lexmarkmodel:printer sharingscope:eqversion:9.41

Trust: 1.6

sources: CNNVD: CNNVD-200602-090 // NVD: CVE-2006-0592

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2006-0592
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200602-090
value: HIGH

Trust: 0.6

VULHUB: VHN-16700
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2006-0592
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-16700
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-16700 // CNNVD: CNNVD-200602-090 // NVD: CVE-2006-0592

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2006-0592

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200602-090

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200602-090

EXTERNAL IDS

db:SECUNIAid:18744

Trust: 1.8

db:SECTRACKid:1015593

Trust: 1.7

db:VUPENid:ADV-2006-0481

Trust: 1.7

db:NVDid:CVE-2006-0592

Trust: 1.7

db:CNNVDid:CNNVD-200602-090

Trust: 0.7

db:BUGTRAQid:20060207 HIGH RISK VULNERABILITY IN LEXMARK PRINTER SHARING SERVICE

Trust: 0.6

db:XFid:24581

Trust: 0.6

db:BIDid:84094

Trust: 0.1

db:VULHUBid:VHN-16700

Trust: 0.1

db:PACKETSTORMid:43675

Trust: 0.1

sources: VULHUB: VHN-16700 // PACKETSTORM: 43675 // CNNVD: CNNVD-200602-090 // NVD: CVE-2006-0592

REFERENCES

url:http://securitytracker.com/id?1015593

Trust: 1.7

url:http://secunia.com/advisories/18744

Trust: 1.7

url:http://www.securityfocus.com/archive/1/424273/100/0/threaded

Trust: 1.1

url:http://www.vupen.com/english/advisories/2006/0481

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/24581

Trust: 1.1

url:http://www.securityfocus.com/archive/1/archive/1/424273/100/0/threaded

Trust: 0.6

url:http://www.frsirt.com/english/advisories/2006/0481

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/24581

Trust: 0.6

url:http://secunia.com/product/7856/

Trust: 0.1

url:http://secunia.com/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/about_secunia_advisories/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/product/7842/

Trust: 0.1

url:http://secunia.com/product/7847/

Trust: 0.1

url:http://secunia.com/advisories/18744/

Trust: 0.1

sources: VULHUB: VHN-16700 // PACKETSTORM: 43675 // CNNVD: CNNVD-200602-090 // NVD: CVE-2006-0592

CREDITS

Secunia

Trust: 0.1

sources: PACKETSTORM: 43675

SOURCES

db:VULHUBid:VHN-16700
db:PACKETSTORMid:43675
db:CNNVDid:CNNVD-200602-090
db:NVDid:CVE-2006-0592

LAST UPDATE DATE

2024-11-23T22:28:39.913000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-16700date:2018-10-19T00:00:00
db:CNNVDid:CNNVD-200602-090date:2006-03-29T00:00:00
db:NVDid:CVE-2006-0592date:2024-11-21T00:06:49.883

SOURCES RELEASE DATE

db:VULHUBid:VHN-16700date:2006-02-08T00:00:00
db:PACKETSTORMid:43675date:2006-02-09T00:56:34
db:CNNVDid:CNNVD-200602-090date:2006-02-07T00:00:00
db:NVDid:CVE-2006-0592date:2006-02-08T01:02:00