CVE-2006-2112

Properties

Published:
23.08.2006
Updated:
30.10.2006
Patch available:
Severity:
High
CVSS vector:
(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)
Product:
Dell: 3000cn
Dell: 3000cn

Vulnerability description

Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, allows remote attackers to use the FTP printing interface as a proxy ("FTP bounce") by using arbitrary PORT arguments to connect to systems for which access would be otherwise restricted.

References:

http://itso.iu.edu/20060824_FXPS_Print_Engine_Vulnerabilities: http://itso.iu.edu/20060824_FXPS_Print_Engine_Vulnerabilities
FRSIRT: http://www.frsirt.com/english/advisories/2006/3401
BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=115652437223454&w=2
BID: http://www.securityfocus.com/bid/19711
XF: http://xforce.iss.net/xforce/xfdb/28637
BUGTRAQ: http://www.securityfocus.com/archive/1/archive/1/444321/100/0/threaded
SECUNIA: http://secunia.com/advisories/21630
OSVDB: http://www.osvdb.org/28249
SECUNIA: http://secunia.com/advisories/22463