7.5
CVSSv2

CVE-2003-0773

Published: 22/09/2003 Updated: 23/08/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

saned in sane-backends 1.0.7 and previous versions does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote malicious users to use that call even if they are restricted in saned.conf.

Vulnerable Product Search on Vulmon Subscribe to Product

sane sane 1.0.0

sane sane 1.0.1

sane sane 1.0.7_beta1

sane sane 1.0.7_beta2

sane sane 1.0.4

sane sane 1.0.5

sane sane 1.0.2

sane sane 1.0.3

sane sane 1.0.8

sane sane 1.0.9

sane sane-backend 1.0.10

sane sane 1.0.6

sane sane 1.0.7

Vendor Advisories

Alexander Hvostov, Julien Blache and Aurelien Jarno discovered several security-related problems in the sane-backends package, which contains an API library for scanners including a scanning daemon (in the package libsane) that can be remotely exploited These problems allow a remote attacker to cause a segmentation fault and/or consume arbitrary a ...