First published: Fri Sep 12 2003(Updated: )
saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sane | =1.0.6 | |
Sane | =1.0.8 | |
Sane | =1.0.5 | |
Sane | =1.0.7_beta1 | |
Sane | =1.0.0 | |
Sane | =1.0.7_beta2 | |
Sane-backends | =1.0.10 | |
Sane | =1.0.9 | |
Sane | =1.0.3 | |
Sane | =1.0.1 | |
Sane | =1.0.2 | |
Sane | =1.0.7 | |
Sane | =1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0777 has a severity rating that indicates it can lead to a denial of service due to a segmentation fault.
To fix CVE-2003-0777, you should upgrade to sane-backends version 1.0.9 or later.
CVE-2003-0777 affects sane-backends versions 1.0.0 through 1.0.8, including several beta versions.
The impact of CVE-2003-0777 can cause dropped connections that prevent strings from being null-terminated, leading to application crashes.
Yes, CVE-2003-0777 is triggered when debug messages are enabled in the affected versions of SANE.