PT-2020-2804 · Sane+6 · Sane-Backends+6
Kevin Backhouse
·
Published
2020-05-17
·
Updated
2022-11-08
·
CVE-2020-12865
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SANE Backends versions prior to 1.0.30
Description
A heap buffer overflow in SANE Backends may allow a malicious device connected to the same local network as the victim to execute arbitrary code. The issue is related to the epsonds component of the sane-backends package and involves a buffer overflow in memory, which can be exploited by a remote attacker to execute arbitrary code or cause a denial of service.
Recommendations
For versions prior to 1.0.30, update to version 1.0.30 or later to resolve the issue. As a temporary workaround, consider restricting access to the network to minimize the risk of exploitation by a malicious device.
Exploit
Fix
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Centos
Linuxmint
Red Hat
Sane-Backends
Suse
Ubuntu