Vulnerabilities > CVE-2020-12867 - NULL Pointer Dereference vulnerability in multiple products

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH

Summary

A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DLA-2231.NASL
    descriptionRemote denial of service and several memory management issues were fixed in the epson2 driver. For Debian 8
    last seen2020-06-06
    modified2020-06-01
    plugin id136987
    published2020-06-01
    reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/136987
    titleDebian DLA-2231-1 : sane-backends security update
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_284813497E204F80AE1EE6BF48D4F17C.NASL
    descriptionThe Sane Project reports : epson2: fixes CVE-2020-12867 (GHSL-2020-075) and several memory management issues found while addressing that CVE epsonds: addresses out-of-bound memory access issues to fix CVE-2020-12862 (GHSL-2020-082) and CVE-2020-12863 (GHSL-2020-083), addresses a buffer overflow fixing CVE-2020-12865 (GHSL-2020-084) and disables network autodiscovery to mitigate CVE-2020-12866 (GHSL-2020-079), CVE-2020-12861 (GHSL-2020-080) and CVE-2020-12864 (GHSL-2020-081). Note that this backend does not support network scanners to begin with. magicolor: fixes a floating point exception and uninitialized data read fixes an overflow in sanei_tcp_read()
    last seen2020-06-06
    modified2020-05-29
    plugin id136955
    published2020-05-29
    reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/136955
    titleFreeBSD : Sane -- Multiple Vulnerabilities (28481349-7e20-4f80-ae1e-e6bf48d4f17c)
  • NASL familySlackware Local Security Checks
    NASL idSLACKWARE_SSA_2020-139-01.NASL
    descriptionNew sane packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
    last seen2020-06-06
    modified2020-05-19
    plugin id136707
    published2020-05-19
    reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/136707
    titleSlackware 14.0 / 14.1 / 14.2 / current : sane (SSA:2020-139-01)