MGASA-2020-0360

Source
https://advisories.mageia.org/MGASA-2020-0360.html
Import Source
https://advisories.mageia.org/MGASA-2020-0360.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0360
Related
Published
2020-09-04T09:16:18Z
Modified
2020-09-04T08:33:41Z
Summary
Updated sane packages fix security vulnerabilities
Details

A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080. (CVE-2020-12861)

An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082. (CVE-2020-12862)

An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083. (CVE-2020-12863)

An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081. (CVE-2020-12864)

A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084. (CVE-2020-12865)

A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079. (CVE-2020-12866)

A NULL pointer dereference in saneiepsonnet_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075. (CVE-2020-12867)

References
Credits

Affected packages

Mageia:7 / sane

Package

Name
sane
Purl
pkg:rpm/mageia/sane?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.28-1.1.mga7

Ecosystem specific

{
    "section": "core"
}