A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080. (CVE-2020-12861) An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious . MGASA-2020-0360 - Updated sane packages fix security vulnerabilities Publication date: 04 Sep 2020 URL: https://advisories.mageia.org/MGASA-2020-0360.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-12861, CVE-2020-12862, CVE-2020-12863, CVE-2020-12864, CVE-2020-12865, CVE-2020-12866, CVE-2020-12867 A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080. (CVE-2020-12861) An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082. (CVE-2020-12862) An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083. (CVE-2020-12863) An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081. (CVE-2020-12864) A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084. (CVE-2020-12865) A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079. (CVE-2020-12866) A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connectedto the same local network as the victim to cause a denial of service, aka GHSL-2020-075. (CVE-2020-12867) References: - https://bugs.mageia.org/show_bug.cgi?id=26712 - https://alioth-lists.debian.net/pipermail/sane-announce/2020/000041.html - https://lists.debian.org/debian-lts-announce/2020/05/msg00036.html - https://lists.debian.org/debian-lts-announce/2020/08/msg00029.html - https://ubuntu.com/security/notices/USN-4470-1 - https://www.cve.org/CVERecord?id=CVE-2020-12861 - https://www.cve.org/CVERecord?id=CVE-2020-12862 - https://www.cve.org/CVERecord?id=CVE-2020-12863 - https://www.cve.org/CVERecord?id=CVE-2020-12864 - https://www.cve.org/CVERecord?id=CVE-2020-12865 - https://www.cve.org/CVERecord?id=CVE-2020-12866 - https://www.cve.org/CVERecord?id=CVE-2020-12867 SRPMS: - 7/core/sane-1.0.28-1.1.mga7 . Essential enhancements for Mageia SANE Backends tackle overflow vulnerabilities and denial-of-service problems. Ensure your security with the newest updates.. sane security patch, Mageia update, buffer overflow fix, DoS prevention. . Severity: Important. LinuxSecurity.com Team
New sane packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] sane (SSA:2020-139-01) New sane packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/sane-1.0.30-i586-1_slack14.2.txz: Upgraded. This update fixes several security issues. For more information, see: https://www.cve.org/CVERecord?id=CVE-2020-12867 https://www.cve.org/CVERecord?id=CVE-2020-12862 https://www.cve.org/CVERecord?id=CVE-2020-12863 https://www.cve.org/CVERecord?id=CVE-2020-12865 https://www.cve.org/CVERecord?id=CVE-2020-12866 https://www.cve.org/CVERecord?id=CVE-2020-12861 https://www.cve.org/CVERecord?id=CVE-2020-12864 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/sane-1.0.30-i486-1_slack14.0.txz Updated package for Slackware x86_64 14.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/sane-1.0.30-x86_64-1_slack14.0.txz Updated package for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/sane-1.0.30-i486-1_slack14.1.txz Updated package for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/sane-1.0.30-x86_64-1_slack14.1.txz Updated package for Slackware 14.2: ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/sane-1.0.30-i586-1_slack14.2.txz Updated package for Slackware x86_6414.2: ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/sane-1.0.30-x86_64-1_slack14.2.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0 package: 8e2b9535b272b8b4aacaa4fa1e95280e sane-1.0.30-i486-1_slack14.0.txz Slackware x86_64 14.0 package: af055a3f9bdbf99f97ad3339d6368486 sane-1.0.30-x86_64-1_slack14.0.txz Slackware 14.1 package: 1a60a73aa33fcad3fcabd88b4661dbee sane-1.0.30-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 7b41b1f224a2646897d6b4397e5fbb79 sane-1.0.30-x86_64-1_slack14.1.txz Slackware 14.2 package: 170980a11078f5b3919e73191d29c776 sane-1.0.30-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 24e8de4fde8bb27e8f8a162e897417ef sane-1.0.30-x86_64-1_slack14.2.txz Slackware -current package: 51ae0f62efa291ef47870410a66ee570 xap/sane-1.0.30-i586-1.txz Slackware x86_64 -current package: 0bad279809bfc8fe2d7d1cec008287f3 xap/sane-1.0.30-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg sane-1.0.30-i586-1_slack14.2.txz +-----+ . Fresh urgent updates for Slackware have been released to tackle significant security vulnerabilities. Promptly update your systems!. Slackware Security, SANE Update, Secure Packages, System Upgrade. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.