CVE-2017-6318: Infoleak
Last updated 25 August 2025
Other sources
saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANENETCONTROLOPTION packet.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sane-backendsto a version that resolves this vulnerability.Fixed in 1.0.31-4.1Fixed in 1.2.1-2Fixed in 1.3.1-3Fixed in 1.4.0-1 - Upgrade
Upgrade
sane-backendsto a version that resolves this vulnerability.Fixed in 1.0.25
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6318?
CVE-2017-6318 is considered a high-severity vulnerability due to the potential for remote attackers to access sensitive memory information.
How do I fix CVE-2017-6318?
To remediate CVE-2017-6318, upgrade the sane-backends package to versions 1.0.31-4.1, 1.2.1-2, or 1.3.0-1 as applicable for your operating system.
Which versions of sane-backends are affected by CVE-2017-6318?
CVE-2017-6318 affects sane-backends version 1.0.25.
Can CVE-2017-6318 be exploited remotely?
Yes, CVE-2017-6318 can be exploited remotely through a crafted SANE_NET_CONTROL_OPTION packet.
What systems are impacted by CVE-2017-6318?
CVE-2017-6318 impacts systems running sane-backends version 1.0.25, particularly in Ubuntu, Debian, and openSUSE environments.