sane-backends: null pointer dereference in epsonds_net_read in epsonds-net.c
Published Jun 24, 2020
5.7
MEDIUMCVSS 3.1
EPSS 1.04%
Description
A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.
Affected products
No data.
Configuration 1
- < 1.0.30
Configuration 2
- 16.04
- 18.04
- 20.04
- 15.1
- 15.2
No data.
Red Hat Enterprise Linux 5
sane-backends
Not affected
Red Hat Enterprise Linux 6
sane-backends
Not affected
Red Hat Enterprise Linux 7
sane-backends
Not affected
Red Hat Enterprise Linux 8
sane-backends
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | sane-backends | Not affected | n/a |
| Red Hat Enterprise Linux 6 | sane-backends | Not affected | n/a |
| Red Hat Enterprise Linux 7 | sane-backends | Not affected | n/a |
| Red Hat Enterprise Linux 8 | sane-backends | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The vulnerable code is a part of "driver for Epson ESC/I-2 scanners" which was first introduced in sane-backends-1.0.25. (via https://gitlab.com/sane-project/backends/-/commit/d72f4663c0ad6e6f779c15c8baf5f92b675ae19a) Therefore only versions of sane-backends shipped with Red Hat Enterprise Linux 8 is affected by this flaw.
Red Hat mitigation
This flaw can be mitigated by limiting network scanner discovery to a trusted subnet via the "net" configuration in the "/etc/sane.d/epsonds.conf" configuration file. Also automatic network scanner discovery can be turned off by commenting out the line "net autodiscovery" in the same configuration file.
References (10)
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00079.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00003.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-12866 Vendor Advisory
- https://alioth-lists.debian.net/pipermail/sane-announce/2020/000041.html x_refsource_CONFIRMMailing ListRelease NotesThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1850549 Issue Tracking
- https://gitlab.com/sane-project/backends/-/issues/279#issue-2-ghsl-2020-079-null-pointer-dereference-in-epsonds_net_read
- https://nvd.nist.gov/vuln/detail/CVE-2020-12866
- https://securitylab.github.com/advisories/GHSL-2020-075-libsane x_refsource_MISCExploitThird Party Advisory
- https://usn.ubuntu.com/4470-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-12866
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00079.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00003.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2020-12866 | Vendor Advisory | |
| https://alioth-lists.debian.net/pipermail/sane-announce/2020/000041.html | x_refsource_CONFIRMMailing ListRelease NotesThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1850549 | Issue Tracking | |
| https://gitlab.com/sane-project/backends/-/issues/279#issue-2-ghsl-2020-079-null-pointer-dereference-in-epsonds_net_read | ||
| https://nvd.nist.gov/vuln/detail/CVE-2020-12866 | ||
| https://securitylab.github.com/advisories/GHSL-2020-075-libsane | x_refsource_MISCExploitThird Party Advisory | |
| https://usn.ubuntu.com/4470-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-12866 |
Change history (0)
No recorded changes yet.