ID

VAR-200603-0105


CVE

CVE-2006-1138


TITLE

Xerox WorkCentre / CopyCentre Multiple unknown vulnerabilities

Trust: 0.6

sources: CNNVD: CNNVD-200603-141

DESCRIPTION

Unspecified vulnerability in the web server code in Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, allows remote attackers to cause a denial of service (memory corruption) via unknown vectors. Xerox WorkCentre / CopyCentre are prone to multiple vulnerabilities. Exploiting these issues can allow remote attackers to trigger a denial-of-service condition in a device. Some of these issues may allow for arbitrary code execution as well, but this is unconfirmed. These software versions are vulnerable: - 1.001.02.073 or prior - Versions greater than 1.001.02.074 but less than 1.001.02.715. 1) An unspecified boundary error in the PostScript file interpreter can be exploited to cause a buffer overflow. Successful exploitation causes a denial of service on a vulnerable device. 2) Two unspecified errors in the handling of PostScript files can be exploited to cause a denial of service on a vulnerable device via a specially crafted PostScript file. 3) An unspecified error in the built-in web server can be exploited to cause a memory corruption. Successful exploitation causes a denial of service on a vulnerable device. 4) An unspecified error in the ESS / Network Controller causes an image overwrite to fail in certain situations after a power loss. * Xerox WorkCentre Pro 65, 75, and 90. SOLUTION: Install System Software Version 1.001.02.074 or 1.001.02.716 (the software versions can be obtained by contacting Xerox customer support). PROVIDED AND/OR DISCOVERED BY: Reported by the vendor. ORIGINAL ADVISORY: http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 1.35

sources: NVD: CVE-2006-1138 // BID: 17014 // VULHUB: VHN-17246 // PACKETSTORM: 44411

AFFECTED PRODUCTS

vendor:xeroxmodel:workcentre pro 65scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:copycentre c65scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:copycentre c90scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:copycentre c65scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:copycentre c65scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:copycentre c75scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:workcentre pro 75scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:workcentre pro 90scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:workcentre pro 75scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:workcentre pro 90scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:copycentre c75scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:copycentre c75scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:workcentre pro 65scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:workcentre pro 65scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:copycentre c90scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:copycentre c90scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:workcentre pro 90scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:workcentre pro 75scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:copycentre c75scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:workcentre 75scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:workcentre 90scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:workcentre 65scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:copycentre c90scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:workcentre 90scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:copycentre c75scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:workcentre 75scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:workcentre 65scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:copycentre c90scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:workcentre proscope:eqversion:90

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:75

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:65

Trust: 0.3

vendor:xeroxmodel:copycentre c90scope:eqversion:0

Trust: 0.3

vendor:xeroxmodel:copycentre c75scope:eqversion:0

Trust: 0.3

vendor:xeroxmodel:copycentre c65scope:eqversion:0

Trust: 0.3

sources: BID: 17014 // CNNVD: CNNVD-200603-141 // NVD: CVE-2006-1138

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2006-1138
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200603-141
value: MEDIUM

Trust: 0.6

VULHUB: VHN-17246
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2006-1138
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-17246
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-17246 // CNNVD: CNNVD-200603-141 // NVD: CVE-2006-1138

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2006-1138

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200603-141

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-200603-141

EXTERNAL IDS

db:BIDid:17014

Trust: 2.0

db:SECUNIAid:19146

Trust: 1.8

db:SECTRACKid:1015738

Trust: 1.7

db:NVDid:CVE-2006-1138

Trust: 1.7

db:OSVDBid:23727

Trust: 1.7

db:VUPENid:ADV-2006-0857

Trust: 1.7

db:CNNVDid:CNNVD-200603-141

Trust: 0.7

db:XFid:25175

Trust: 0.6

db:VULHUBid:VHN-17246

Trust: 0.1

db:PACKETSTORMid:44411

Trust: 0.1

sources: VULHUB: VHN-17246 // BID: 17014 // PACKETSTORM: 44411 // CNNVD: CNNVD-200603-141 // NVD: CVE-2006-1138

REFERENCES

url:http://www.xerox.com/downloads/usa/en/c/cert_xrx06_002.pdf

Trust: 1.8

url:http://www.securityfocus.com/bid/17014

Trust: 1.7

url:http://www.osvdb.org/23727

Trust: 1.7

url:http://securitytracker.com/id?1015738

Trust: 1.7

url:http://secunia.com/advisories/19146

Trust: 1.7

url:http://www.vupen.com/english/advisories/2006/0857

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/25175

Trust: 1.1

url:http://www.frsirt.com/english/advisories/2006/0857

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/25175

Trust: 0.6

url:http://a1851.g.akamaitech.net/f/1851/2996/24h/cacheb.xerox.com/downloads/usa/en/c/cert_xrx06_002v11.pdf

Trust: 0.3

url:http://secunia.com/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/product/8595/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/product/4553/

Trust: 0.1

url:http://secunia.com/advisories/19146/

Trust: 0.1

url:http://secunia.com/about_secunia_advisories/

Trust: 0.1

sources: VULHUB: VHN-17246 // BID: 17014 // PACKETSTORM: 44411 // CNNVD: CNNVD-200603-141 // NVD: CVE-2006-1138

CREDITS

Xerox

Trust: 0.6

sources: CNNVD: CNNVD-200603-141

SOURCES

db:VULHUBid:VHN-17246
db:BIDid:17014
db:PACKETSTORMid:44411
db:CNNVDid:CNNVD-200603-141
db:NVDid:CVE-2006-1138

LAST UPDATE DATE

2024-08-14T14:00:23.403000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-17246date:2018-10-04T00:00:00
db:BIDid:17014date:2006-10-23T22:08:00
db:CNNVDid:CNNVD-200603-141date:2006-03-13T00:00:00
db:NVDid:CVE-2006-1138date:2018-10-04T22:11:30.157

SOURCES RELEASE DATE

db:VULHUBid:VHN-17246date:2006-03-10T00:00:00
db:BIDid:17014date:2006-03-07T00:00:00
db:PACKETSTORMid:44411date:2006-03-08T04:17:23
db:CNNVDid:CNNVD-200603-141date:2006-03-09T00:00:00
db:NVDid:CVE-2006-1138date:2006-03-10T02:02:00