• sane-backends vulnerabilities

    From bugz_ubuntu@21:4/110 to Ubuntu Users on Monday, August 24, 2020 16:10:01
    sane-backends vulnerabilities

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 20.04 LTS
    * Ubuntu 18.04 LTS
    * Ubuntu 16.04 LTS

    Summary

    Several security issues were fixed in sane-backends.

    Software Description

    * sane-backends - None

    Details

    Kritphong Mongkhonvanit discovered that sane-backends incorrectly
    handled certain packets. A remote attacker could possibly use this
    issue to obtain sensitive memory information. This issue only
    affected Ubuntu 16.04 LTS. (CVE-2017-6318)

    It was discovered that sane-backends incorrectly handled certain
    memory operations. A remote attacker could possibly use this issue
    to execute arbitrary code. This issue only applied to Ubuntu 18.04
    LTS and Ubuntu 20.04 LTS. (CVE-2020-12861)

    It was discovered that sane-backends incorrectly handled certain
    memory operations. A remote attacker could possibly use this issue
    to obtain sensitive information. (CVE-2020-12862, CVE-2020-12863)

    It was discovered that sane-backends incorrectly handled certain
    memory operations. A remote attacker could possibly use this issue
    to obtain sensitive information. This issue only applied to Ubuntu
    18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-12864)

    It was discovered that sane-backends incorrectly handled certain
    memory operations. A remote attacker could possibly use this issue
    to execute arbitrary code. (CVE-2020-12865)

    It was discovered that sane-backends incorrectly handled certain
    memory operations. A remote attacker could possibly use this issue
    to cause a denial of service. This issue only applied to Ubuntu
    18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-12866)

    It was discovered that sane-backends incorrectly handled certain
    memory operations. A remote attacker could possibly use this issue
    to cause a denial of service. (CVE-2020-12867)

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 20.04 LTS
    libsane1 - 1.0.29-0ubuntu5.1

    Ubuntu 18.04 LTS
    libsane1 - 1.0.27-1~experimental3ubuntu2.3

    Ubuntu 16.04 LTS
    libsane - 1.0.25+git20150528-1ubuntu2.16.04.3

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    In general, a standard system update will make all the necessary
    changes.

    References

    * CVE-2017-6318
    * CVE-2020-12861
    * CVE-2020-12862
    * CVE-2020-12863
    * CVE-2020-12864
    * CVE-2020-12865
    * CVE-2020-12866
    * CVE-2020-12867

    --- Mystic BBS v1.12 A45 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)