CVE-2019-10627
Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-compatible interpreters due to incorrect buffer size calculation. in PostScript and PDF printers that use IPS versions prior to 2019.2 in…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-compatible interpreters due to incorrect buffer size calculation. in PostScript and PDF printers that use IPS versions prior to 2019.2 in PostScript and PDF printers that use IPS versions prior to 2019.2
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.35% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-131, CWE-190
- Affected
- qualcomm/ips · hp/d9l63a firmware · hp/d9l64a firmware · hp/t0g70a firmware · hp/j3p65a firmware · hp/j3p68a firmware · hp/j6u57a firmware · hp/j6u57b firmware · hp/j9v80a firmware · hp/j9v80b firmware · hp/j6u55a firmware · hp/j6u55d firmware · hp/j6u51b firmware · hp/j9v82a firmware · hp/j9v82d firmware · hp/j9v78b firmware · hp/d3q15a firmware · hp/d3q15b firmware · hp/d3q15d firmware · hp/d3q16a firmware · +22 more
- Source
- product-security@qualcomm.com
References
- https://support.hp.com/us-en/document/c06458150Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/october-2019-bulletinThird Party Advisory
- https://support.hp.com/us-en/document/c06458150Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/october-2019-bulletinThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.