CVE编号
CVE-2020-12867利用情况
暂无补丁情况
官方补丁披露时间
2020-06-02漏洞描述
SANE Backends是一款用于调节软件与数字成像设备之间通信的应用程序编程接口(API)和通信协议。<br /> SANE Backends 1.0.30之前版本存在空指针解引用漏洞。该漏洞源于程序未正确处理某些内存操作。攻击者可利用该漏洞导致拒绝服务。解决建议
目前厂商已发布升级补丁以修复漏洞,详情请关注厂商主页:http://www.sane-project.org/
参考链接 |
|
---|---|
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00079.html | |
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00003.html | |
https://alioth-lists.debian.net/pipermail/sane-announce/2020/000041.html | |
https://gitlab.com/sane-project/backends/-/issues/279#issue-1-ghsl-2020-075-n... | |
https://lists.debian.org/debian-lts-announce/2020/08/msg00029.html | |
https://lists.debian.org/debian-lts-announce/2020/10/msg00010.html | |
https://lists.fedoraproject.org/archives/list/[email protected]... | |
https://securitylab.github.com/advisories/GHSL-2020-075-libsane | |
https://usn.ubuntu.com/4470-1/ |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
系统 | alpine_3.12 | sane | * |
Up to (excluding) 1.0.30-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.13 | sane | * |
Up to (excluding) 1.0.30-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.14 | sane | * |
Up to (excluding) 1.0.30-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.15 | sane | * |
Up to (excluding) 1.0.30-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_edge | sane | * |
Up to (excluding) 1.0.30-r0 |
|||||
运行在以下环境 | |||||||||
系统 | centos_8 | sane | * |
Up to (excluding) 1.0.27-22.el8 |
|||||
运行在以下环境 | |||||||||
系统 | debian_10 | sane | * |
Up to (excluding) 1.0.27-3.2 |
|||||
运行在以下环境 | |||||||||
系统 | debian_11 | sane | * |
Up to (excluding) 1.0.31-3 |
|||||
运行在以下环境 | |||||||||
系统 | debian_8 | sane | * |
Up to (excluding) 1.0.24-8+deb8u2 |
|||||
运行在以下环境 | |||||||||
系统 | debian_9 | sane | * |
Up to (excluding) 1.0.25-4.1+deb9u1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_sid | sane | * |
Up to (excluding) 1.0.31-3 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_32 | sane | * |
Up to (excluding) 1.0.30-1.fc32 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_15.1 | sane | * |
Up to (excluding) 1.0.31-lp151.6.3.1 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_15.2 | sane | * |
Up to (excluding) 1.0.31-lp152.7.3.1 |
|||||
运行在以下环境 | |||||||||
系统 | oracle_8 | sane | * |
Up to (excluding) 1.0.27-22.el8 |
|||||
运行在以下环境 | |||||||||
系统 | redhat_8 | sane | * |
Up to (excluding) 1.0.27-22.el8 |
|||||
运行在以下环境 | |||||||||
系统 | sane-project | sane_backends | * |
Up to (including) 1.0.29 |
|||||
运行在以下环境 | |||||||||
系统 | sles_12_SP5 | sane | * |
Up to (excluding) 1.0.31-4.3.1 |
|||||
运行在以下环境 | |||||||||
系统 | suse_12_SP5 | sane | * |
Up to (excluding) 1.0.31-4.3.1 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_16.04 | sane | * |
Up to (excluding) 1.0.25+git20150528-1ubuntu2.16.04.3 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_16.04_lts | sane-backends | * |
Up to (excluding) 1.0.25+git20150528-1ubuntu2.16.04.3 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_18.04 | sane | * |
Up to (excluding) 1.0.27-1~experimental3ubuntu2.3 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_18.04_lts | sane-backends | * |
Up to (excluding) 1.0.27-1~experimental3ubuntu2.3 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_20.04 | sane | * |
Up to (excluding) 1.0.29-0ubuntu5.1 |
|||||
运行在以下环境 | |||||||||
系统 | unionos_20 | sane | * |
Up to (excluding) 1.0.30-1+eagle |
|||||
运行在以下环境 | |||||||||
硬件 | sane-project | sane_backends | - | - | |||||
- 攻击路径 本地
- 攻击复杂度 复杂
- 权限要求 普通权限
- 影响范围 有限影响
- EXP成熟度 未验证
- 补丁情况 官方补丁
- 数据保密性 无影响
- 数据完整性 无影响
- 服务器危害 无影响
- 全网数量 100
还没有评论,来说两句吧...