CVE-2023-46047: Input Validation
An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the saneiconfigureattach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controlled configuration file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-46047?
CVE-2023-46047 is classified as a local code execution vulnerability that could pose significant risks based on its exploitation.
How do I fix CVE-2023-46047?
To fix CVE-2023-46047, ensure that the Sane software is updated to a patched version that mitigates this vulnerability.
Who is affected by CVE-2023-46047?
CVE-2023-46047 affects users of Sane version 1.2.1 due to the vulnerability in the sanei_configure_attach() function.
Can CVE-2023-46047 be exploited remotely?
No, CVE-2023-46047 requires a local attacker to exploit the vulnerability.
Is there a workaround for CVE-2023-46047?
A specific workaround for CVE-2023-46047 is not publicly documented, so updating to the latest version is recommended for protection.