CVE-2023-0856: Buffer Overflow
Buffer overflow in IPP sides attribute process of Office / Small Office Multifunction Printers and Laser Printers() which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. :Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0856?
CVE-2023-0856 has been classified as a critical vulnerability because it may allow attackers to execute arbitrary code or crash affected printers.
How do I fix CVE-2023-0856?
To mitigate CVE-2023-0856, users should update their affected Canon multifunction printers and laser printers to firmware version greater than 11.04.
Which devices are affected by CVE-2023-0856?
CVE-2023-0856 affects several Canon multifunction printers and laser printers, particularly those running firmware version 11.04 or lower.
What is a buffer overflow in the context of CVE-2023-0856?
In CVE-2023-0856, a buffer overflow occurs when too much data is sent to a print job, potentially leading to system crashes or arbitrary code execution.
Can an attacker exploit CVE-2023-0856 remotely?
Yes, an attacker on the same network segment could exploit CVE-2023-0856 without needing physical access to the affected printer.