CVE-2020-12862

Source
https://cve.org/CVERecord?id=CVE-2020-12862
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-12862.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-12862
Downstream
Related
Published
2020-06-24T13:15:11.020Z
Modified
2026-02-10T16:40:38.523450Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.

References

Affected packages

Git / gitlab.com/sane-project/backends

Affected ranges

Type
GIT
Repo
https://gitlab.com/sane-project/backends
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*
1.0.27
1.0.28
1.0.29
Other
BETA_1_0_10_1
BETA_1_0_10_2
BETA_1_0_10_3
BETA_1_0_12_1
BETA_1_0_12_2
BETA_1_0_14_1
BETA_1_0_14_2
BETA_1_0_14_3
BETA_1_0_15_1
BETA_1_0_15_2
BETA_1_0_7-1
BETA_1_0_7-2
BETA_1_0_8-1
BETA_1_0_9_2
DEVEL_2_0_TRUNK-1
RELEASE_1_0_1
RELEASE_1_0_10
RELEASE_1_0_11_TRUNK
RELEASE_1_0_12
RELEASE_1_0_13
RELEASE_1_0_14
RELEASE_1_0_15
RELEASE_1_0_16
RELEASE_1_0_17
RELEASE_1_0_18
RELEASE_1_0_19
RELEASE_1_0_2
RELEASE_1_0_20
RELEASE_1_0_21
RELEASE_1_0_22
RELEASE_1_0_23_FIXED2
RELEASE_1_0_24
RELEASE_1_0_25
RELEASE_1_0_27
RELEASE_1_0_3
RELEASE_1_0_4
RELEASE_1_0_5
RELEASE_1_0_6
RELEASE_1_0_7
RELEASE_1_0_8
RELEASE_1_0_9
gitconversion

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-12862.json"