ZeroHour
Cisco Talospublished ()ingested Nick Biasini

Vulnerability Spotlight: Lexmark Perceptive Document Filters Code Execution Bugs

highVulnerability exploited in the wildimportance 60CVE-2017-2821CVE-2017-2822

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-2821
+1 in the same advisory: …2822
An exploitable use-after-free exists in the PDF parsing functionality of Lexmark Perspective Document Filters 11.3.0.2400 and 11.4.0.2452.

An exploitable use-after-free exists in the PDF parsing functionality of Lexmark Perspective Document Filters 11.3.0.2400 and 11.4.0.2452. A crafted PDF document can lead to a use-after-free resulting in direct code execution.

NVD description · AI analysis pending
8.82%
  • lexmark perceptive document filters
Full article249 words · extracted from blog.talosintelligence.com · click to collapse

Monday, August 28, 2017 11:30

Overview

Talos is disclosing a pair of code execution vulnerabilities in Lexmark Perceptive Document Filters. Perceptive Document Filters are a series of libraries that are used to parse massive amounts of different types of file formats for multiple purposes. Talos has previously discussed in detail these filters and how they operate. The software update to resolve these vulnerabilities can be found here.

TALOS-2017-0322

Discovered by Marcin Noga of Cisco Talos

TALOS-2017-0322 / CVE-2017-2821 is a code execution vulnerability in the PDF parsing functionality of the Lexmark Perceptive Document Filters. This particular vulnerability is an use-after-free issue related to the 'GfxFont' variable and can be triggered via a specially crafted PDF document resulting in code execution. Full details of the vulnerability are available here.

TALOS-2017-0323

Discovered by Marcin Noga & Lillyth Wyatt of Cisco Talos

TALOS-2017-0323 / CVE-2017-2822 is a code execution vulnerability in the image rendering functionality of Lexmark Perceptive Document Filters. This particular vulnerability can be triggered via a specially crafted PDF document causing a function call to a corrupted DCTStream, eventually resulting in user controlled data being written to the stack. Full details of the vulnerability are available here.

Coverage

The following Snort rules will detect exploitation attempts. Note that additional rules may be released at a future date, and current rules are subject to change pending additional vulnerability information. For the most current rule information, please refer to your FireSIGHT Management Center or Snort.org.

Snort Rule: 42313-42314, 42399-42400

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/lexmark-perceptive-filters-vuln/