漏洞信息详情
Fuji Xerox Printing Systems嵌入式HTTP服务器多个漏洞
- CNNVD编号:CNNVD-200608-400
- 危害等级: 中危
- CVE编号:
CVE-2006-2113
- 漏洞类型:
授权问题
- 发布时间:
2006-08-24
- 威胁类型:
远程
- 更新时间:
2006-10-30
- 厂 商:
dell - 漏洞来源:
Sean Krulewitch is… -
漏洞简介
Fuji Xerox Printing Systems (FXPS) 打印引擎的嵌入式HTTP服务器,当用于以下软件,包括:(1) Dell 3000cn至5110cn版本,和(2) Fuji Xerox DocuPrint firmware 20060628之前的版本以及Network Option Card硬件5.13之前的版本时,没有对HTTP请求进行正确认证,远程攻击者可借助特制的请求修改系统配置,包括修改管理员密码或触发打印服务器拒绝服务攻击。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Fuji Xerox Printing Systems Co. DocuPrint C830 0
Fuji Xerox Printing Systems Co. C83F0607.EXE
http://download.fujixerox.co.jp/docuprint_c/download/830/fw.html
Fuji Xerox Printing Systems Co. Phaser 6201J 0
Fuji Xerox Printing Systems Co. 6201N513.EXE
http://www.fxpsc.co.jp/download/fw/fw_6201.html
Fuji Xerox Printing Systems Co. DocuPrint C525A Network Option Card 0
Fuji Xerox Printing Systems Co. N5250817.EXE
http://download.fujixerox.co.jp/docuprint_c/download/525a/nic_fw.html
Fuji Xerox Printing Systems Co. DocuPrint C1616 0
Fuji Xerox Printing Systems Co. C16F0607.EXE
http://download.fujixerox.co.jp/docuprint_c/download/1616/fw.html
Fuji Xerox Printing Systems Co. DocuPrint 181 0
Fuji Xerox Printing Systems Co. 181F0607.EXE
http://download.fujixerox.co.jp/docuprint/download/211series/181_firm. html
Fuji Xerox Printing Systems Co. DocuPrint C525A 0
Fuji Xerox Printing Systems Co. C5250614.EXE
http://download.fujixerox.co.jp/docuprint_c/download/525a/fw.html
Fuji Xerox Printing Systems Co. DocuPrint 211 0
Fuji Xerox Printing Systems Co. 211F0607.EXE
http://download.fujixerox.co.jp/docuprint/download/211series/211_firm. html
Fuji Xerox Printing Systems Co. DocuPrint C830 Network Option Card 0
Fuji Xerox Printing Systems Co. C83N513.EXE
http://download.fujixerox.co.jp/docuprint_c/download/830/nic_fw.html
参考网址
来源: MISC
链接:http://itso.iu.edu/20060824_FXPS_Print_Engine_Vulnerabilities
来源: BID
名称: 19716
链接:http://www.securityfocus.com/bid/19716
来源: BUGTRAQ
名称: 20060825 Indiana University Security Advisory: Fuji Xerox Printing Systems (FXPS) print engine vulnerabilities
链接:http://www.securityfocus.com/archive/1/archive/1/444321/100/0/threaded
来源: OSVDB
名称: 28250
来源: VUPEN
名称: ADV-2006-3401
链接:http://www.frsirt.com/english/advisories/2006/3401
来源: SECUNIA
名称: 22463
链接:http://secunia.com/advisories/22463
来源: SECUNIA
名称: 21630
链接:http://secunia.com/advisories/21630
来源: BUGTRAQ
名称: 20060825 Indiana University Security Advisory: Fuji Xerox Printing Systems (FXPS) print engine vulnerabilitie
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=115652437223454&w=2