5
CVSSv2

CVE-2003-0775

Published: 22/09/2003 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

saned in sane-backends 1.0.7 and previous versions calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote malicious users to cause a denial of service (memory consumption or crash).

Vulnerable Product Search on Vulmon Subscribe to Product

sane sane 1.0.8

sane sane 1.0.9

sane sane 1.0.2

sane sane 1.0.3

sane sane 1.0.4

sane sane 1.0.5

sane sane-backend 1.0.10

sane sane 1.0.1

sane sane 1.0.6

sane sane 1.0.7_beta1

sane sane 1.0.0

sane sane 1.0.7

sane sane 1.0.7_beta2

Vendor Advisories

Alexander Hvostov, Julien Blache and Aurelien Jarno discovered several security-related problems in the sane-backends package, which contains an API library for scanners including a scanning daemon (in the package libsane) that can be remotely exploited These problems allow a remote attacker to cause a segmentation fault and/or consume arbitrary a ...