|
Xerox Phaser Products Denial of Service Vulnerability
|
|
Secunia Advisory:
|
SA31329
|
|
|
Release Date:
|
2008-08-06
|
|
Last Update:
|
2008-09-24
|
|
Popularity:
|
1,609 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
DoS
|
|
Where:
|
From local network
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Xerox Phaser 6200 Xerox Phaser 7300 Xerox Phaser 7750 Xerox Phaser 8400
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2008-3571
|
|
Description: crit3rion has reported a vulnerability in multiple Xerox Phaser products, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error in the processing of empty UDP packets received on port 1900 and can be exploited to reboot an affected device.
The vulnerability affects the following products and versions:
* Xerox Phaser 6200 prior to firmware version 2.20
* Xerox Phaser 7300 prior to firmware version 2.16
* Xerox Phaser 7750 prior to firmware version 5.0.2
* Xerox Phaser 8400
Solution: Apply a fixed firmware version where available. Please see the vendor's advisory for more information.
Provided and/or discovered by: crit3rion
Changelog: 2008-08-13: Added CVE reference.
2008-09-24: Added Xerox Phaser 6200/7300/7750 to the list of affected products. Updated the "Solution" and "Original Advisory" sections.
Original Advisory: Xerox:
http://www.xerox.com/downloads/usa/en/c/cert_XRX08_010.pdf
crit3rion:
http://milw0rm.com/exploits/6196
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|