5.7
CVE-2020-12866
- EPSS 1.04%
- Veröffentlicht 24.06.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:26
- Erkennungen
A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sane-project ≫ Sane Backends Version < 1.0.30
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.04% | 0.595 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.7 | 2.1 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 2.7 | 5.1 | 2.9 |
AV:A/AC:L/Au:S/C:N/I:N/A:P
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
https://usn.ubuntu.com/4470-1/
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00079.html
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00003.html
https://alioth-lists.debian.net/pipermail/sane-announce/2020/000041.html
https://securitylab.github.com/advisories/GHSL-2020-075-libsane