5.5
CVE-2020-12867
- EPSS 0.5%
- Veröffentlicht 01.06.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:00:27
- Erkennungen
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sane-project ≫ Sane Backends Version < 1.0.30
Fedoraproject ≫ Fedora Version 32
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.5% | 0.386 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:N/I:N/A:P
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
https://usn.ubuntu.com/4470-1/
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00079.html
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00003.html
https://alioth-lists.debian.net/pipermail/sane-announce/2020/000041.html
https://gitlab.com/sane-project/backends/-/issues/279#issue-1-ghsl-2020-075-null-pointer-dereference-in-sanei_epson_net_read
https://lists.debian.org/debian-lts-announce/2020/08/msg00029.html
https://lists.debian.org/debian-lts-announce/2020/10/msg00010.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWUVCHURVGGYBEUOBA4PLSNXJVBKHJYJ/
https://securitylab.github.com/advisories/GHSL-2020-075-libsane