CVE-2003-0773: High severity SANE SANE vulnerability
saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANENETINIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the saned service (sane-backends) so only trusted hosts can reach it. Implement firewall/ACL rules or host-based firewall rules to allow connections to saned only from known/trusted IPs, and block or filter SANE_NET_INIT RPC calls from untrusted networks.
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0773?
CVE-2003-0773 is classified as a medium severity vulnerability due to unauthorized access risk.
How do I fix CVE-2003-0773?
To fix CVE-2003-0773, update to a fixed version of sane-backends, such as 1.0.10 or later.
What are the affected versions for CVE-2003-0773?
CVE-2003-0773 affects sane-backends versions 1.0.0 through 1.0.8, including various beta versions.
What are the potential impacts of CVE-2003-0773?
The potential impacts of CVE-2003-0773 include unauthorized access allowing attackers to perform unauthorized RPC calls.
Is CVE-2003-0773 specific to certain operating systems?
CVE-2003-0773 is not limited to specific operating systems, as it affects the SANE Project's software across various platforms.