Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian: 380-2 Critical: LibXML2 Buffer Overflow Vulnerability

debian
Calendar Grey September 11, 2003
Scroller Debian
- -------------------------------------------------------------------------- Debian Security Advisor
Thes problems allowa remote attacker to cause a segfault fault and/or consume arbitraryamounts of memory.

Summary

Alexander Hvostov, Julien Blache and Aurelien Jarno discovered several
security-related problems in the sane-backends package, which contains
an API library for scanners including a scanning daemon (in the
package libsane) that can be remotely exploited. Thes problems allow
a remote attacker to cause a segfault fault and/or consume arbitrary
amounts of memory. The attack is successful, even if the attacker's
computer isn't listed in saned.conf.

You are only vulnerable if you actually run saned e.g. in xinetd or
inetd. If the entries in the configuration file of xinetd or inetd
respectively are commented out or do not exist, you are safe.

Try "telnet localhost 6566" on the server that may run saned. If you
get "connection refused" saned is not running and you are safe.

The Common Vulnerabilities and Exposures project identifies the
following problems:

CAN-2003-0773:

saned checks the identity (IP address) of the remote host only
after the first communication took place (SANE_NET_INIT). So
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: sane-backends

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.