ID

VAR-200603-0097


CVE

CVE-2006-1137


TITLE

Xerox WorkCentre / CopyCentre Multiple unknown vulnerabilities

Trust: 0.6

sources: CNNVD: CNNVD-200603-129

DESCRIPTION

Multiple unspecified vulnerabilities in Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, allow remote attackers to cause an unspecified denial of service via a crafted PostScript file that will (1) "navigate through the directory" or (2) a "file sent to expose TCP/IP ports". Xerox WorkCentre / CopyCentre are prone to multiple vulnerabilities. Exploiting these issues can allow remote attackers to trigger a denial-of-service condition in a device. Some of these issues may allow for arbitrary code execution as well, but this is unconfirmed. These software versions are vulnerable: - 1.001.02.073 or prior - Versions greater than 1.001.02.074 but less than 1.001.02.715. 1) An unspecified boundary error in the PostScript file interpreter can be exploited to cause a buffer overflow. Successful exploitation causes a denial of service on a vulnerable device. 3) An unspecified error in the built-in web server can be exploited to cause a memory corruption. Successful exploitation causes a denial of service on a vulnerable device. 4) An unspecified error in the ESS / Network Controller causes an image overwrite to fail in certain situations after a power loss. * Xerox WorkCentre Pro 65, 75, and 90. SOLUTION: Install System Software Version 1.001.02.074 or 1.001.02.716 (the software versions can be obtained by contacting Xerox customer support). PROVIDED AND/OR DISCOVERED BY: Reported by the vendor. ORIGINAL ADVISORY: http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 1.35

sources: NVD: CVE-2006-1137 // BID: 17014 // VULHUB: VHN-17245 // PACKETSTORM: 44411

AFFECTED PRODUCTS

vendor:xeroxmodel:copycentre c65scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:copycentre c65scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:copycentre c90scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:copycentre c65scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:workcentre pro 65scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:workcentre pro 90scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:workcentre pro 65scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:workcentre pro 75scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:workcentre pro 75scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:workcentre pro 65scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:workcentre pro 90scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:copycentre c75scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:workcentre pro 90scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:copycentre c75scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:workcentre pro 75scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:copycentre c90scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:copycentre c75scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:copycentre c90scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:copycentre c75scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:workcentre 75scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:workcentre 90scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:workcentre 65scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:copycentre c90scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:workcentre 90scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:copycentre c75scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:workcentre 75scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:workcentre 65scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:copycentre c90scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:workcentre proscope:eqversion:90

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:75

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:65

Trust: 0.3

vendor:xeroxmodel:copycentre c90scope:eqversion:0

Trust: 0.3

vendor:xeroxmodel:copycentre c75scope:eqversion:0

Trust: 0.3

vendor:xeroxmodel:copycentre c65scope:eqversion:0

Trust: 0.3

sources: BID: 17014 // CNNVD: CNNVD-200603-129 // NVD: CVE-2006-1137

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2006-1137
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200603-129
value: MEDIUM

Trust: 0.6

VULHUB: VHN-17245
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2006-1137
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-17245
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-17245 // CNNVD: CNNVD-200603-129 // NVD: CVE-2006-1137

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2006-1137

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200603-129

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-200603-129

EXTERNAL IDS

db:BIDid:17014

Trust: 2.0

db:SECUNIAid:19146

Trust: 1.8

db:SECTRACKid:1015738

Trust: 1.7

db:OSVDBid:23725

Trust: 1.7

db:OSVDBid:23726

Trust: 1.7

db:NVDid:CVE-2006-1137

Trust: 1.7

db:VUPENid:ADV-2006-0857

Trust: 1.7

db:CNNVDid:CNNVD-200603-129

Trust: 0.7

db:XFid:25174

Trust: 0.6

db:XFid:25173

Trust: 0.6

db:VULHUBid:VHN-17245

Trust: 0.1

db:PACKETSTORMid:44411

Trust: 0.1

sources: VULHUB: VHN-17245 // BID: 17014 // PACKETSTORM: 44411 // CNNVD: CNNVD-200603-129 // NVD: CVE-2006-1137

REFERENCES

url:http://www.xerox.com/downloads/usa/en/c/cert_xrx06_002.pdf

Trust: 1.8

url:http://www.securityfocus.com/bid/17014

Trust: 1.7

url:http://www.osvdb.org/23725

Trust: 1.7

url:http://www.osvdb.org/23726

Trust: 1.7

url:http://securitytracker.com/id?1015738

Trust: 1.7

url:http://secunia.com/advisories/19146

Trust: 1.7

url:http://www.vupen.com/english/advisories/2006/0857

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/25173

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/25174

Trust: 1.1

url:http://www.frsirt.com/english/advisories/2006/0857

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/25174

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/25173

Trust: 0.6

url:http://a1851.g.akamaitech.net/f/1851/2996/24h/cacheb.xerox.com/downloads/usa/en/c/cert_xrx06_002v11.pdf

Trust: 0.3

url:http://secunia.com/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/product/8595/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/product/4553/

Trust: 0.1

url:http://secunia.com/advisories/19146/

Trust: 0.1

url:http://secunia.com/about_secunia_advisories/

Trust: 0.1

sources: VULHUB: VHN-17245 // BID: 17014 // PACKETSTORM: 44411 // CNNVD: CNNVD-200603-129 // NVD: CVE-2006-1137

CREDITS

Xerox

Trust: 0.6

sources: CNNVD: CNNVD-200603-129

SOURCES

db:VULHUBid:VHN-17245
db:BIDid:17014
db:PACKETSTORMid:44411
db:CNNVDid:CNNVD-200603-129
db:NVDid:CVE-2006-1137

LAST UPDATE DATE

2024-11-23T22:20:07.396000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-17245date:2018-10-04T00:00:00
db:BIDid:17014date:2006-10-23T22:08:00
db:CNNVDid:CNNVD-200603-129date:2006-03-13T00:00:00
db:NVDid:CVE-2006-1137date:2024-11-21T00:08:09.970

SOURCES RELEASE DATE

db:VULHUBid:VHN-17245date:2006-03-10T00:00:00
db:BIDid:17014date:2006-03-07T00:00:00
db:PACKETSTORMid:44411date:2006-03-08T04:17:23
db:CNNVDid:CNNVD-200603-129date:2006-03-09T00:00:00
db:NVDid:CVE-2006-1137date:2006-03-10T02:02:00