Back to Database
Status published
High
CVE-2003-0776
saned in sane-backends 1.0.7 and earlier does not properly "check...
Vulnerability Description
saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2003-0776
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.redhat.com/support/errata/RHSA-2003-278.html
- ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt
- http://www.novell.com/linux/security/advisories/2003_046_sane.html
- http://www.redhat.com/support/errata/RHSA-2003-285.html
- http://www.securityfocus.com/bid/8593
- http://www.debian.org/security/2003/dsa-379
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:099
More from sane
View All →CVE-2003-0778
saned in sane-backends 1.0.7 and earlier, and possibly later versions,...
Medium
5
CVE-2003-0777
saned in sane-backends 1.0.7 and earlier, when debug messages are...
Medium
5
CVE-2003-0775
saned in sane-backends 1.0.7 and earlier calls malloc with an...
Medium
5
CVE-2003-0774
saned in sane-backends 1.0.7 and earlier does not quickly handle...
High
7.5
CVE-2003-0773
saned in sane-backends 1.0.7 and earlier does not check the...
High
7.5
Affected Vendor
sane
View all reports →Affected Software
sane, sane-backend
Vulnerable Versions:
1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.7_beta1, 1.0.7_beta2, 1.0.8, 1.0.9, 1.0.10
Timeline
Official Publish:
September 12th, 2003
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.