漏洞信息详情
Fuji Xerox Printing System FTP跳转攻击漏洞
- CNNVD编号:CNNVD-200608-407
- 危害等级: 高危
- CVE编号:
CVE-2006-2112
- 漏洞类型:
权限许可和访问控制
- 发布时间:
2006-08-24
- 威胁类型:
远程
- 更新时间:
2006-10-30
- 厂 商:
dell - 漏洞来源:
Nate Johnson and S… -
漏洞简介
Fuji Xerox Printing Systems (FXPS)打印引擎,应用于以下软件时:(1) Dell 3000cn至5110cn,以及(2) Fuji Xerox DocuPrint硬件20060628之前版本及Network Option Card硬件5.13之前版本,远程攻击者可通过使用任意PORT自变量连接到限制直接访问的系统,从而将FTP打印接口用作代理服务器(\”FTP跳转攻击\”)。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Fuji Xerox Printing Systems Co. DocuPrint C830 0
Fuji Xerox Printing Systems Co. C83F0607.EXE
http://download.fujixerox.co.jp/docuprint_c/download/830/fw.html
Fuji Xerox Printing Systems Co. Phaser 6201J 0
Fuji Xerox Printing Systems Co. 6201N513.EXE
http://www.fxpsc.co.jp/download/fw/fw_6201.html
Fuji Xerox Printing Systems Co. DocuPrint C525A Network Option Card 0
Fuji Xerox Printing Systems Co. N5250817.EXE
http://download.fujixerox.co.jp/docuprint_c/download/525a/nic_fw.html
Fuji Xerox Printing Systems Co. DocuPrint C1616 0
Fuji Xerox Printing Systems Co. C16F0607.EXE
http://download.fujixerox.co.jp/docuprint_c/download/1616/fw.html
Fuji Xerox Printing Systems Co. DocuPrint 181 0
Fuji Xerox Printing Systems Co. 181F0607.EXE
http://download.fujixerox.co.jp/docuprint/download/211series/181_firm. html
Fuji Xerox Printing Systems Co. DocuPrint C525A 0
Fuji Xerox Printing Systems Co. C5250614.EXE
http://download.fujixerox.co.jp/docuprint_c/download/525a/fw.html
Fuji Xerox Printing Systems Co. DocuPrint 211 0
Fuji Xerox Printing Systems Co. 211F0607.EXE
http://download.fujixerox.co.jp/docuprint/download/211series/211_firm. html
Fuji Xerox Printing Systems Co. DocuPrint C830 Network Option Card 0
Fuji Xerox Printing Systems Co. C83N513.EXE
http://download.fujixerox.co.jp/docuprint_c/download/830/nic_fw.html
参考网址
来源: MISC
链接:http://itso.iu.edu/20060824_FXPS_Print_Engine_Vulnerabilities
来源: XF
名称: fxps-port-security-bypass(28637)
链接:http://xforce.iss.net/xforce/xfdb/28637
来源: BID
名称: 19711
链接:http://www.securityfocus.com/bid/19711
来源: BUGTRAQ
名称: 20060825 Indiana University Security Advisory: Fuji Xerox Printing Systems (FXPS) print engine vulnerabilities
链接:http://www.securityfocus.com/archive/1/archive/1/444321/100/0/threaded
来源: OSVDB
名称: 28249
来源: VUPEN
名称: ADV-2006-3401
链接:http://www.frsirt.com/english/advisories/2006/3401
来源: SECUNIA
名称: 22463
链接:http://secunia.com/advisories/22463
来源: SECUNIA
名称: 21630
链接:http://secunia.com/advisories/21630
来源: BUGTRAQ
名称: 20060825 Indiana University Security Advisory: Fuji Xerox Printing Systems (FXPS) print engine vulnerabilitie
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=115652437223454&w=2