CVE-2020-12863: Medium severity Sane-project Sane Backends vulnerability
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12863?
CVE-2020-12863 is classified as a high severity vulnerability due to its potential for exploitation through out-of-bounds reads.
How do I fix CVE-2020-12863?
To fix CVE-2020-12863, upgrade to SANE Backends version 1.0.30 or later, depending on your specific distribution.
What types of systems are affected by CVE-2020-12863?
CVE-2020-12863 affects SANE Backends versions prior to 1.0.30 across various Linux distributions including Ubuntu and Debian.
Can CVE-2020-12863 be exploited remotely?
Yes, CVE-2020-12863 can be exploited by a malicious device on the same local network as the vulnerable system.
What information can be leaked due to CVE-2020-12863?
CVE-2020-12863 may allow an attacker to read sensitive data such as ASLR offsets of the program.