OSVDB ID: 13138

Title: Xerox WorkCentre Pro PostScript Traversal Arbitrary File Access

Info

Disclosure

Jan 24, 2005

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

WorkCentre Pro contains a flaw that may allow a malicious user to gain unauthorized access to arbitrary files. The issue is due to an input validation error in the ESS/ Network Controller within the PostScript file interpretation code. It is possible that the flaw may allow disclosure of the arbitrary files (e.g. encrypted password file) via a specially crafted PostScript file containing directory traversal characters (../), resulting in a loss of confidentiality.

Classification

Location: Remote/Network Access Required
Attack Type: Information Disclosure, Input Manipulation
Impact: Loss of Confidentiality
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, vendor has released a patch to address this vulnerability.

Products

XEROX CORPORATION

WorkCentre Pro

01.02.083

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/36218