SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-10627

Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-compatible interpreters due to incorrect buffer size calculation. in PostScript and PDF printers that use IPS versions prior to 2019.2 in…

CRITICAL 9.8EPSS 1.35%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-compatible interpreters due to incorrect buffer size calculation. in PostScript and PDF printers that use IPS versions prior to 2019.2 in PostScript and PDF printers that use IPS versions prior to 2019.2

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.35% probability · 70th percentile
CISA KEV
Not listed
Weakness
CWE-119, CWE-131, CWE-190
Affected
qualcomm/ips · hp/d9l63a firmware · hp/d9l64a firmware · hp/t0g70a firmware · hp/j3p65a firmware · hp/j3p68a firmware · hp/j6u57a firmware · hp/j6u57b firmware · hp/j9v80a firmware · hp/j9v80b firmware · hp/j6u55a firmware · hp/j6u55d firmware · hp/j6u51b firmware · hp/j9v82a firmware · hp/j9v82d firmware · hp/j9v78b firmware · hp/d3q15a firmware · hp/d3q15b firmware · hp/d3q15d firmware · hp/d3q16a firmware · +22 more
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.