7.5
CVSSv3

CVE-2017-6318

Published: 20/03/2017 Updated: 01/09/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

saned in sane-backends 1.0.25 allows remote malicious users to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse leap 42.1

sane-backends project sane-backends 1.0.25

Vendor Advisories

Debian Bug report logs - #854804 saned: CVE-2017-6318: SANE_NET_CONTROL_OPTION response packet may contain memory contents of the server Package: sane-utils; Maintainer for sane-utils is Jörg Frings-Fürst <debian@jffemail>; Source for sane-utils is src:sane-backends (PTS, buildd, popcon) Reported by: Kritphong Mongkhonvan ...