CVE Vulnerabilities

CVE-2003-0773

Published: Sep 22, 2003 | Modified: Aug 23, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.

Affected Software

Name Vendor Start Version End Version
Sane Sane 1.0.0 (including) 1.0.0 (including)
Sane Sane 1.0.1 (including) 1.0.1 (including)
Sane Sane 1.0.2 (including) 1.0.2 (including)
Sane Sane 1.0.3 (including) 1.0.3 (including)
Sane Sane 1.0.4 (including) 1.0.4 (including)
Sane Sane 1.0.5 (including) 1.0.5 (including)
Sane Sane 1.0.6 (including) 1.0.6 (including)
Sane Sane 1.0.7 (including) 1.0.7 (including)
Sane Sane 1.0.7_beta1 (including) 1.0.7_beta1 (including)
Sane Sane 1.0.7_beta2 (including) 1.0.7_beta2 (including)
Sane Sane 1.0.8 (including) 1.0.8 (including)
Sane Sane 1.0.9 (including) 1.0.9 (including)
Sane-backend Sane 1.0.10 (including) 1.0.10 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 RedHat *
Red Hat Enterprise Linux ES version 2.1 RedHat *
Red Hat Enterprise Linux WS version 2.1 RedHat *
Red Hat Linux 7.1 RedHat *
Red Hat Linux 7.2 RedHat *
Red Hat Linux 7.3 RedHat *
Red Hat Linux 8.0 RedHat *
Red Hat Linux Advanced Workstation 2.1 RedHat *

References