CVE Vulnerabilities

CVE-2003-0773

Published: Sep 22, 2003 | Modified: Aug 23, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.

Affected Software

Name Vendor Start Version End Version
Sane Sane 1.0.0 (including) 1.0.0 (including)
Sane Sane 1.0.1 (including) 1.0.1 (including)
Sane Sane 1.0.2 (including) 1.0.2 (including)
Sane Sane 1.0.3 (including) 1.0.3 (including)
Sane Sane 1.0.4 (including) 1.0.4 (including)
Sane Sane 1.0.5 (including) 1.0.5 (including)
Sane Sane 1.0.6 (including) 1.0.6 (including)
Sane Sane 1.0.7 (including) 1.0.7 (including)
Sane Sane 1.0.7_beta1 (including) 1.0.7_beta1 (including)
Sane Sane 1.0.7_beta2 (including) 1.0.7_beta2 (including)
Sane Sane 1.0.8 (including) 1.0.8 (including)
Sane Sane 1.0.9 (including) 1.0.9 (including)
Sane-backend Sane 1.0.10 (including) 1.0.10 (including)

References