CVE-2020-12864: Medium severity Sane-project Sane Backends vulnerability
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sane-backendsto a version that resolves this vulnerability.Fixed in 1.0.31-4.1Fixed in 1.2.1-2Fixed in 1.3.1-3Fixed in 1.4.0-1 - Upgrade
Upgrade
SANE Backendsto a version that resolves this vulnerability.Fixed in 1.0.30Patch GHSL-2020-081
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12864?
CVE-2020-12864 has a high severity rating due to the potential for an out-of-bounds read that could expose sensitive information.
How do I fix CVE-2020-12864?
To fix CVE-2020-12864, update to SANE Backends version 1.0.30 or later.
Which versions of SANE Backends are affected by CVE-2020-12864?
SANE Backends versions prior to 1.0.30 are vulnerable to CVE-2020-12864.
Can CVE-2020-12864 be exploited remotely?
Yes, CVE-2020-12864 can be exploited by a malicious device on the same local network.
What platforms are impacted by CVE-2020-12864?
CVE-2020-12864 affects multiple platforms including specific Ubuntu and Debian versions.