ID

VAR-200603-0106


CVE

CVE-2006-1139


TITLE

Xerox CopyCentre and Xerox WorkCentre Pro ESS/ Network Controller Unknown vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200603-160

DESCRIPTION

Unspecified vulnerability in the ESS/ Network Controller in Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, causes the Immediate Image Overwrite feature to fail after a power loss, which could leave data exposed to attack. CopyCentre C75 is prone to a remote security vulnerability. TITLE: Xerox CopyCentre / WorkCentre Pro Multiple Denial of Service Vulnerabilities SECUNIA ADVISORY ID: SA19146 VERIFY ADVISORY: http://secunia.com/advisories/19146/ CRITICAL: Moderately critical IMPACT: Unknown, DoS WHERE: >From remote OPERATING SYSTEM: Xerox CopyCentre http://secunia.com/product/8595/ Xerox WorkCentre Pro http://secunia.com/product/4553/ DESCRIPTION: Some vulnerabilities have been reported in Xerox CopyCentre and Xerox WorkCentre Pro, where one has an unknown impact, and others can be exploited by malicious people to cause a DoS (Denial of Service). 1) An unspecified boundary error in the PostScript file interpreter can be exploited to cause a buffer overflow. Successful exploitation causes a denial of service on a vulnerable device. 2) Two unspecified errors in the handling of PostScript files can be exploited to cause a denial of service on a vulnerable device via a specially crafted PostScript file. 3) An unspecified error in the built-in web server can be exploited to cause a memory corruption. Successful exploitation causes a denial of service on a vulnerable device. The vulnerabilities affect the following products: * Xerox CopyCentre C65, C75, and C90. * Xerox WorkCentre Pro 65, 75, and 90. SOLUTION: Install System Software Version 1.001.02.074 or 1.001.02.716 (the software versions can be obtained by contacting Xerox customer support). PROVIDED AND/OR DISCOVERED BY: Reported by the vendor. ORIGINAL ADVISORY: http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 1.35

sources: NVD: CVE-2006-1139 // BID: 88044 // VULHUB: VHN-17247 // PACKETSTORM: 44411

AFFECTED PRODUCTS

vendor:xeroxmodel:workcentre pro 65scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:copycentre c65scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:copycentre c90scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:copycentre c65scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:copycentre c65scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:copycentre c75scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:workcentre pro 75scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:workcentre pro 90scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:workcentre pro 75scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:workcentre pro 90scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:copycentre c75scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:copycentre c75scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:workcentre pro 65scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:workcentre pro 65scope:gteversion:1.001.02.074

Trust: 1.0

vendor:xeroxmodel:copycentre c90scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:copycentre c90scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:workcentre pro 90scope:lteversion:1.001.02.073

Trust: 1.0

vendor:xeroxmodel:workcentre pro 75scope:ltversion:1.001.02.715

Trust: 1.0

vendor:xeroxmodel:copycentre c75scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:workcentre 75scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:workcentre 90scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:workcentre 65scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:copycentre c90scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:workcentre 90scope:eqversion:1.001.02.0715

Trust: 0.6

vendor:xeroxmodel:copycentre c75scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:workcentre 75scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:workcentre 65scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:copycentre c90scope:eqversion:1.001.02.073

Trust: 0.6

vendor:xeroxmodel:workcentre proscope:eqversion:901.001.02.073

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:901.001.02.0715

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:751.001.02.073

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:751.001.02.0715

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:651.001.02.073

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:651.001.02.0715

Trust: 0.3

sources: BID: 88044 // CNNVD: CNNVD-200603-160 // NVD: CVE-2006-1139

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2006-1139
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200603-160
value: MEDIUM

Trust: 0.6

VULHUB: VHN-17247
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2006-1139
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-17247
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-17247 // CNNVD: CNNVD-200603-160 // NVD: CVE-2006-1139

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2006-1139

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200603-160

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200603-160

EXTERNAL IDS

db:SECTRACKid:1015738

Trust: 2.0

db:NVDid:CVE-2006-1139

Trust: 2.0

db:SECUNIAid:19146

Trust: 1.8

db:OSVDBid:23728

Trust: 1.7

db:VUPENid:ADV-2006-0857

Trust: 1.7

db:XFid:25176

Trust: 0.9

db:CNNVDid:CNNVD-200603-160

Trust: 0.7

db:BIDid:88044

Trust: 0.3

db:VULHUBid:VHN-17247

Trust: 0.1

db:PACKETSTORMid:44411

Trust: 0.1

sources: VULHUB: VHN-17247 // BID: 88044 // PACKETSTORM: 44411 // CNNVD: CNNVD-200603-160 // NVD: CVE-2006-1139

REFERENCES

url:http://www.xerox.com/downloads/usa/en/c/cert_xrx06_002.pdf

Trust: 2.1

url:http://securitytracker.com/id?1015738

Trust: 2.0

url:http://www.osvdb.org/23728

Trust: 1.7

url:http://secunia.com/advisories/19146

Trust: 1.7

url:http://www.vupen.com/english/advisories/2006/0857

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/25176

Trust: 1.1

url:http://xforce.iss.net/xforce/xfdb/25176

Trust: 0.9

url:http://www.frsirt.com/english/advisories/2006/0857

Trust: 0.6

url:http://secunia.com/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/product/8595/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/product/4553/

Trust: 0.1

url:http://secunia.com/advisories/19146/

Trust: 0.1

url:http://secunia.com/about_secunia_advisories/

Trust: 0.1

sources: VULHUB: VHN-17247 // BID: 88044 // PACKETSTORM: 44411 // CNNVD: CNNVD-200603-160 // NVD: CVE-2006-1139

CREDITS

Unknown

Trust: 0.3

sources: BID: 88044

SOURCES

db:VULHUBid:VHN-17247
db:BIDid:88044
db:PACKETSTORMid:44411
db:CNNVDid:CNNVD-200603-160
db:NVDid:CVE-2006-1139

LAST UPDATE DATE

2024-08-14T14:00:23.465000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-17247date:2018-10-04T00:00:00
db:BIDid:88044date:2006-03-09T00:00:00
db:CNNVDid:CNNVD-200603-160date:2006-03-13T00:00:00
db:NVDid:CVE-2006-1139date:2018-10-04T22:11:20.843

SOURCES RELEASE DATE

db:VULHUBid:VHN-17247date:2006-03-10T00:00:00
db:BIDid:88044date:2006-03-09T00:00:00
db:PACKETSTORMid:44411date:2006-03-08T04:17:23
db:CNNVDid:CNNVD-200603-160date:2006-03-09T00:00:00
db:NVDid:CVE-2006-1139date:2006-03-10T02:02:00