Canon Generic Plus Printer Drivers Buffer Overflow Vulnerability Allowing Code Execution

Vulnerability

A buffer overflow vulnerability has been identified in several Canon Generic Plus printer drivers, including PCL6, UFR II, LIPS4, LIPSLX, PS, FAX, UFRII LT, and CARPS2. This vulnerability arises during EMF Recode processing when printing from a manipulated application, potentially leading to out-of-bounds memory access. Under certain conditions, the vulnerability could disrupt printing processes or allow unauthorized code execution, although such occurrences are believed to be rare.

Impact

Exploitation of this vulnerability could cause a buffer overflow, leading to out-of-bounds memory access. This could disrupt printing operations or allow for the execution of arbitrary code.

Remediation

Users are advised to update to the latest version of the affected printer drivers. For those using the uniFLOW SmartClient driver package, version 2025.1.2 is available as of April 4, 2025.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
10.0
exploitability
4.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.