CVE-2017-6318Sensitive Information Exposure in Project Sane-backends

Severity
7.5HIGHNVD
EPSS
0.7%
top 27.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20
Latest updateMay 13

Description

saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Ubuntusane-backends_project/sane-backends< 1.0.25+git20150528-1ubuntu2.16.04.3+2
NVDopensuse/leap42.1

🔴Vulnerability Details

4
GHSA
GHSA-r29j-hp6g-537x: saned in sane-backends 12022-05-13
OSV
sane-backends vulnerabilities2020-08-24
CVEList
CVE-2017-6318: saned in sane-backends 12017-03-20
OSV
CVE-2017-6318: saned in sane-backends 12017-03-20

📋Vendor Advisories

3
Ubuntu
sane-backends vulnerabilities2020-08-24
Debian
CVE-2017-6318: sane-backends - saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory...2017
Red Hat
sane-backends: SANE_NET_CONTROL_OPTION response packet may contain memory contents of the server2016-12-16

💬Community

3
Bugzilla
CVE-2017-6318 mingw-sane-backends: sane-backends: SANE_NET_CONTROL_OPTION response packet may contain memory contents of the server [fedora-all]2017-03-03
Bugzilla
CVE-2017-6318 sane-backends: SANE_NET_CONTROL_OPTION response packet may contain memory contents of the server2017-03-03
Bugzilla
CVE-2017-6318 sane-backends: SANE_NET_CONTROL_OPTION response packet may contain memory contents of the server [fedora-all]2017-03-03
CVE-2017-6318 — Sensitive Information Exposure | cvebase