CVE-2020-12867
on gitlab
Published
Severity
CVSS v3:
5.5 MEDIUM
CVSS v2:
2.1 LOW
Description
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.
References
- https://gitlab.com/sane-project/backends/-/issues/279#issue-1-ghsl-2020-075-null-pointer-dereference-in-sanei_epson_net_read
- https://alioth-lists.debian.net/pipermail/sane-announce/2020/000041.html
- https://securitylab.github.com/advisories/GHSL-2020-075-libsane
- https://lists.fedoraproject.org/archives/list/[email protected]/message/JWUVCHURVGGYBEUOBA4PLSNXJVBKHJYJ/
- https://lists.debian.org/debian-lts-announce/2020/08/msg00029.html
- https://usn.ubuntu.com/4470-1/
- https://lists.debian.org/debian-lts-announce/2020/10/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00079.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWUVCHURVGGYBEUOBA4PLSNXJVBKHJYJ/
Configurations
CPE23 | Version Start | Version End | Exact Version |
---|---|---|---|
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | n/a | n/a | 32 |
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | n/a | n/a | 9.0 |
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* | n/a | n/a | 15.1 |
cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:* | n/a | n/a | 15.2 |
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | n/a | n/a | 18.04 |
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:* | n/a | n/a | 20.04 |
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* | n/a | n/a | 16.04 |