PT-2020-6486 · Unknown+6 · Sane-Backends+6
Kevin Backhouse
·
Published
2020-04-21
·
Updated
2023-06-12
·
CVE-2020-12861
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SANE Backends versions prior to 1.0.30
Description
A heap buffer overflow in the SANE Backends allows a malicious device connected to the same local network as the victim to execute arbitrary code. The vulnerability is related to the
epsonds net read function in the epsonds-net.c component of the SANE API for scanning raster images. Exploitation of the vulnerability may allow an attacker to access confidential data, compromise its integrity, and cause a denial of service.Recommendations
For versions prior to 1.0.30, update to version 1.0.30 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable
epsonds-net.c component until a patch is available. Avoid using the epsonds net read function in the affected API endpoint until the issue is resolved.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Centos
Linuxmint
Red Hat
Sane-Backends
Suse
Ubuntu