HP JetDirect contains an overflow condition in the TouchSmart functionality. The issue is triggered as user-supplied input is not properly validated when changing the name of the FTP service, which uploads scanned jobs from multi-function printers. When intercepting a connection request, a remote attacker can manipulate the request to cause the device to enter restore mode and force a user to perform a firmware reload to recover.
Disclosure Timeline:
Disclosure Date :2013-01-01
Exploit Publish Date :2013-01-02