PT-2020-2804 · Sane+6 · Sane-Backends+6

Kevin Backhouse

·

Published

2020-05-17

·

Updated

2022-11-08

·

CVE-2020-12865

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SANE Backends versions prior to 1.0.30
Description A heap buffer overflow in SANE Backends may allow a malicious device connected to the same local network as the victim to execute arbitrary code. The issue is related to the epsonds component of the sane-backends package and involves a buffer overflow in memory, which can be exploited by a remote attacker to execute arbitrary code or cause a denial of service.
Recommendations For versions prior to 1.0.30, update to version 1.0.30 or later to resolve the issue. As a temporary workaround, consider restricting access to the network to minimize the risk of exploitation by a malicious device.

Exploit

Fix

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02932
CESA-2020_2902
CVE-2020-12865
DLA-2332-1
DLA-2332-2
MGASA-2020-0360
OESA-2021-1074
OPENSUSE-SU-2020:1791-1
OPENSUSE-SU-2020:1798-1
OPENSUSE-SU-2020_1791-1
OPENSUSE-SU-2020_1798-1
OPENSUSE-SU-2024:11366-1
RHSA-2020:2902
RHSA-2020:2967
RHSA-2020:3045
RHSA-2020_2902
SUSE-SU-2020:3065-1
SUSE-SU-2020:3125-1
USN-4470-1

Affected Products

Astra Linux
Centos
Linuxmint
Red Hat
Sane-Backends
Suse
Ubuntu