CVE Vulnerabilities

CVE-2003-0773

Published: Sep 22, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.

Affected Software

NameVendorStart VersionEnd Version
SaneSane1.0.0 (including)1.0.0 (including)
SaneSane1.0.1 (including)1.0.1 (including)
SaneSane1.0.2 (including)1.0.2 (including)
SaneSane1.0.3 (including)1.0.3 (including)
SaneSane1.0.4 (including)1.0.4 (including)
SaneSane1.0.5 (including)1.0.5 (including)
SaneSane1.0.6 (including)1.0.6 (including)
SaneSane1.0.7 (including)1.0.7 (including)
SaneSane1.0.7_beta1 (including)1.0.7_beta1 (including)
SaneSane1.0.7_beta2 (including)1.0.7_beta2 (including)
SaneSane1.0.8 (including)1.0.8 (including)
SaneSane1.0.9 (including)1.0.9 (including)
Sane-backendSane1.0.10 (including)1.0.10 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.2RedHat*
Red Hat Linux 7.3RedHat*
Red Hat Linux 8.0RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*

References