CVE-2019-10627

CRITICALCVSS 9.8/10EPSS 1.39%

Last modified

CVE-2019-10627 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-compatible interpreters due to incorrect buffer size calculation. in PostScript and PDF printers that use IPS versions prior to 2019.2 in PostScript and PDF printers that use IPS versions prior to 2019.2. EPSS estimates a 1.39% chance of exploitation in the next 30 days.

Description

Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-compatible interpreters due to incorrect buffer size calculation. in PostScript and PDF printers that use IPS versions prior to 2019.2 in PostScript and PDF printers that use IPS versions prior to 2019.2

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.39%

68.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
QualcommIps< 2019.2
HpD9l63a Firmware< 001.1937c
HpD9l64a Firmware< 001.1937c
HpT0g70a Firmware< 001.1937c
HpJ3p65a Firmware< 001.1937c
HpJ3p68a Firmware< 001.1937c
HpJ6u57a Firmware< 001.1937d
HpJ6u57b Firmware< 001.1937d
HpJ9v80a Firmware< 001.1937d
HpJ9v80b Firmware< 001.1937d
HpJ6u55a Firmware< 001.1937d
HpJ6u55d Firmware< 001.1937d
HpJ6u51b Firmware< 001.1937d
HpJ9v82a Firmware< 001.1937d
HpJ9v82d Firmware< 001.1937d
HpJ9v78b Firmware< 001.1937d
HpD3q15a Firmware< 001.1937d
HpD3q15b Firmware< 001.1937d
HpD3q15d Firmware< 001.1937d
HpD3q16a Firmware< 001.1937d
HpD3q16d Firmware< 001.1937d
HpW2z52b Firmware< 001.1937d
HpD3q19a Firmware< 001.1937d
HpD3q19b Firmware< 001.1937d
HpD3q19d Firmware< 001.1937d
HpD3q20a Firmware< 001.1937d
HpD3q20b Firmware< 001.1937d
HpD3q20c Firmware< 001.1937d
HpD3q20d Firmware< 001.1937d
HpW2z53b Firmware< 001.1937d
Hp2dr21d Firmware< 001.1937d
HpD3q17a Firmware< 001.1937d
HpD3q17d Firmware< 001.1937d
HpK9z74a Firmware< 001.1937d
HpK9z74d Firmware< 001.1937d
HpD3q21a Firmware< 001.1937d
HpD3q21b Firmware< 001.1937d
HpD3q21c Firmware< 001.1937d
HpD3q21d Firmware< 001.1937d
HpK9z76a Firmware< 001.1937d
HpK9z76b Firmware< 001.1937d
HpK9z76d Firmware< 001.1937d

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-10627?
Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-compatible interpreters due to incorrect buffer size calculation. in PostScript and PDF printers that use IPS versions prior to 2019.2 in PostScript and PDF printers that use IPS versions prior to 2019.2
How severe is CVE-2019-10627?
CVE-2019-10627 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.39% probability of exploitation in the next 30 days.
How do I fix CVE-2019-10627?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-10627?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST