CVE-2021-44738 – Lexmark MC3224i PostScript Out-Of-Bounds Write Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-44738
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter. Se ha identificado una vulnerabilidad de desbordamiento del búfer en los dispositivos Lexmark versiones hasta 07-12-2021, en el intérprete de postscript This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lexmark MC3224i printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of PostScript data. Crafted PostScript data can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. • https://support.lexmark.com/alerts https://www.zerodayinitiative.com/advisories/ZDI-22-327 https://www.zerodayinitiative.com/advisories/ZDI-22-328 https://www.zerodayinitiative.com/advisories/ZDI-22-382 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2018-15520
https://notcve.org/view.php?id=CVE-2018-15520
Various Lexmark devices have a Buffer Overflow (issue 2 of 2). Varios dispositivos Lexmark tienen un desbordamiento de búfer (problema 2 de 2). • http://support.lexmark.com/index?page=content&id=TE892 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •