CVE-2017-6318

NameCVE-2017-6318
Descriptionsaned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-940-1
Debian Bugs854804

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
sane-backends (PTS)jessie, jessie (lts)1.0.24-8+deb8u3fixed
stretch (security), stretch (lts), stretch1.0.25-4.1+deb9u2fixed
buster1.0.27-3.2fixed
bullseye1.0.31-4.1fixed
bookworm1.2.1-2fixed
sid, trixie1.3.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
sane-backendssourcewheezy1.0.22-7.4+deb7u1DLA-940-1
sane-backendssourcejessie1.0.24-8+deb8u2
sane-backendssource(unstable)1.0.25-4low854804

Notes

Upstream patch: https://anonscm.debian.org/cgit/sane/sane-backends.git/commit/frontend/saned.c?id=42896939822b44f44ecd1b6d35afdfa4473ed35d

Search for package or bug name: Reporting problems