saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sane | Sane | 1.0.0 (including) | 1.0.0 (including) |
Sane | Sane | 1.0.1 (including) | 1.0.1 (including) |
Sane | Sane | 1.0.2 (including) | 1.0.2 (including) |
Sane | Sane | 1.0.3 (including) | 1.0.3 (including) |
Sane | Sane | 1.0.4 (including) | 1.0.4 (including) |
Sane | Sane | 1.0.5 (including) | 1.0.5 (including) |
Sane | Sane | 1.0.6 (including) | 1.0.6 (including) |
Sane | Sane | 1.0.7 (including) | 1.0.7 (including) |
Sane | Sane | 1.0.7_beta1 (including) | 1.0.7_beta1 (including) |
Sane | Sane | 1.0.7_beta2 (including) | 1.0.7_beta2 (including) |
Sane | Sane | 1.0.8 (including) | 1.0.8 (including) |
Sane | Sane | 1.0.9 (including) | 1.0.9 (including) |
Sane-backend | Sane | 1.0.10 (including) | 1.0.10 (including) |
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | RedHat | * | |
Red Hat Enterprise Linux ES version 2.1 | RedHat | * | |
Red Hat Enterprise Linux WS version 2.1 | RedHat | * | |
Red Hat Linux 7.1 | RedHat | * | |
Red Hat Linux 7.2 | RedHat | * | |
Red Hat Linux 7.3 | RedHat | * | |
Red Hat Linux 8.0 | RedHat | * | |
Red Hat Linux Advanced Workstation 2.1 | RedHat | * |