Security Basics mailing list archives

Security of PCL and PostScript


From: Paul Johnston <paj () pajhome org uk>
Date: Tue, 13 May 2008 18:13:00 +0100

Hi,

I've been told a few times PCL and PostScript are fully functional
stack-based languages. Had anyone successfully compromised a printer, by
submitting a job that contains malicious PCl or PostScript? I'd be
particularly interested to know if this is an inherent weakness with the
languages, or a specific vulnerability that has existed in some versions of
printer firmware, but been patched since.

Regards,

Paul


Current thread: