CVE-2020-12867

Name
CVE-2020-12867
Description
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory https://gitlab.com/sane-project/backends/-/issues/279#issue-1-ghsl-2020-075-null-pointer-dereference-in-sanei_epson_net_read
Mailing List https://alioth-lists.debian.net/pipermail/sane-announce/2020/000041.html
MISC https://securitylab.github.com/advisories/GHSL-2020-075-libsane
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JWUVCHURVGGYBEUOBA4PLSNXJVBKHJYJ/
MLIST https://lists.debian.org/debian-lts-announce/2020/08/msg00029.html
UBUNTU https://usn.ubuntu.com/4470-1/
MLIST https://lists.debian.org/debian-lts-announce/2020/10/msg00010.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00003.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00079.html

Match rules

CPE URI Source package Min version Max version

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
sane edge-community 1.0.30-r0 None fixed
sane 3.22-community 1.0.30-r0 None fixed
sane 3.21-community 1.0.30-r0 None fixed
sane 3.20-community 1.0.30-r0 None fixed
sane 3.19-community 1.0.30-r0 None fixed
sane 3.18-community 1.0.30-r0 None fixed
sane 3.17-community 1.0.30-r0 None fixed