Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-6318

Опубликовано: 16 дек. 2016
Источник: redhat
CVSS3: 3.7

Описание

saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.

An information disclosure flaw was found in the way saned handled SANE_NET_CONTROL_OPTION requests. A remote attacker, able to connect to the saned daemon, could use this flaw to disclose portions of saned process memory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sane-backendsWill not fix
Red Hat Enterprise Linux 6sane-backendsWill not fix
Red Hat Enterprise Linux 7sane-backendsWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1428883sane-backends: SANE_NET_CONTROL_OPTION response packet may contain memory contents of the server

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.

CVSS3: 7.5
nvd
почти 9 лет назад

saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.

CVSS3: 7.5
debian
почти 9 лет назад

saned in sane-backends 1.0.25 allows remote attackers to obtain sensit ...

suse-cvrf
почти 9 лет назад

Security update for sane-backends

suse-cvrf
почти 9 лет назад

Security update for sane-backends

3.7 Low

CVSS3