Vulnerability Description
Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed with an attacker-controlled configuration file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sane-Project | Sane Backends | 1.2.1 |
References
- http://seclists.org/fulldisclosure/2024/Jan/69Mailing ListThird Party Advisory
- https://gitlab.com/sane-project/backends/-/issues/709ExploitIssue Tracking
- http://packetstormsecurity.com/files/176823/sane-1.2.1-Buffer-Overflow.html
- http://seclists.org/fulldisclosure/2024/Jan/69Mailing ListThird Party Advisory
- https://gitlab.com/sane-project/backends/-/issues/709ExploitIssue Tracking
FAQ
What is CVE-2023-46052?
CVE-2023-46052 is a vulnerability with a CVSS score of 7.1 (HIGH). Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code shou...
How severe is CVE-2023-46052?
CVE-2023-46052 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-46052?
Check the references section above for vendor advisories and patch information. Affected products include: Sane-Project Sane Backends.