Secunia Logo
 
Debian update for sane-backends
Secunia Advisory: SA9710
Release Date: 2003-09-11
Popularity: 6,047 views

Critical:
Less critical
Impact: DoS
Where: From local network
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.0
Debian GNU/Linux unstable alias sid

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2003-0773
CVE-2003-0774
CVE-2003-0775
CVE-2003-0776
CVE-2003-0777
CVE-2003-0778


Description:
Debian has issued updated packages for sane-backends. These fix several vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerabilities are caused due to various errors that all can be exploited to either crash the service or cause it to consume an excessive amount of memory resources.

Successful exploitation requires that saned is running but the malicious system does not have to be listed in "saned.conf".

Solution:
Updated packages:

-- Debian GNU/Linux 3.0 alias woody --

Source archives:

http://security.debian.org/pool/updat...ne-backends/sane-backends_1.0.7-4.dsc
Size/MD5 checksum: 650 fce2bccda1eca4e4185deee5681f738f
http://security.debian.org/pool/updat...ackends/sane-backends_1.0.7-4.diff.gz
Size/MD5 checksum: 27898 56454dddbb589c56c5404c3228c0e4e8
http://security.debian.org/pool/updat...kends/sane-backends_1.0.7.orig.tar.gz
Size/MD5 checksum: 1867577 6010d68d8a8c29d1dcbf0c6d5005770b

Alpha architecture:

http://security.debian.org/pool/updat...ne-backends/libsane_1.0.7-4_alpha.deb
Size/MD5 checksum: 1797436 3cc566a8518565d305f8d81d3fa6d766
http://security.debian.org/pool/updat...ackends/libsane-dev_1.0.7-4_alpha.deb
Size/MD5 checksum: 5560004 5b99bc14cb5207a656ed0f11b9f43d05

ARM architecture:

http://security.debian.org/pool/updat...sane-backends/libsane_1.0.7-4_arm.deb
Size/MD5 checksum: 1590972 2a1255e8be662d9415096eec2cc33d8e
http://security.debian.org/pool/updat...-backends/libsane-dev_1.0.7-4_arm.deb
Size/MD5 checksum: 4750680 20fba2388a627f9504cbc621873e2d7a

Intel IA-32 architecture:

http://security.debian.org/pool/updat...ane-backends/libsane_1.0.7-4_i386.deb
Size/MD5 checksum: 1451240 c0726d631d9426eaecd8aaa2667eb801
http://security.debian.org/pool/updat...backends/libsane-dev_1.0.7-4_i386.deb
Size/MD5 checksum: 4524636 37934f30ed8726f7f39791cfb2760bb5

Intel IA-64 architecture:

http://security.debian.org/pool/updat...ane-backends/libsane_1.0.7-4_ia64.deb
Size/MD5 checksum: 2240324 3efa00ae110d3dae825b39685d24ff93
http://security.debian.org/pool/updat...backends/libsane-dev_1.0.7-4_ia64.deb
Size/MD5 checksum: 4892446 9ce7e0ff7db5e7bebe6b9c5497d9c855

HP Precision architecture:

http://security.debian.org/pool/updat...ane-backends/libsane_1.0.7-4_hppa.deb
Size/MD5 checksum: 1762866 7a2d25d300f2aef6972c656f1cf0918e
http://security.debian.org/pool/updat...backends/libsane-dev_1.0.7-4_hppa.deb
Size/MD5 checksum: 5099552 d529ee8a61cd316ae2d19d1ecf2ae249

Motorola 680x0 architecture:

http://security.debian.org/pool/updat...ane-backends/libsane_1.0.7-4_m68k.deb
Size/MD5 checksum: 1447178 b499ce366fc07a291b00edcacdf2312d
http://security.debian.org/pool/updat...backends/libsane-dev_1.0.7-4_m68k.deb
Size/MD5 checksum: 4410546 40a8fb70043f6f84e0cd7a02d1428b31

Big endian MIPS architecture:

http://security.debian.org/pool/updat...ane-backends/libsane_1.0.7-4_mips.deb
Size/MD5 checksum: 1488654 f9e09f27924d704d35dec4ab2b42c84d
http://security.debian.org/pool/updat...backends/libsane-dev_1.0.7-4_mips.deb
Size/MD5 checksum: 4859694 08ec5fdf4c847800d82935fbe782179f

Little endian MIPS architecture:

http://security.debian.org/pool/updat...e-backends/libsane_1.0.7-4_mipsel.deb
Size/MD5 checksum: 1490928 87a4f046310a9e76917fa16df8271c3d
http://security.debian.org/pool/updat...ckends/libsane-dev_1.0.7-4_mipsel.deb
Size/MD5 checksum: 4624290 314367f2ea0ef4328a1a904236452528

PowerPC architecture:

http://security.debian.org/pool/updat...-backends/libsane_1.0.7-4_powerpc.deb
Size/MD5 checksum: 1597728 b9b3588129d046d76b1bde2f20d51e4a
http://security.debian.org/pool/updat...kends/libsane-dev_1.0.7-4_powerpc.deb
Size/MD5 checksum: 4913074 6e7d5fcf31ccff0be85b9b6855a117b4

IBM S/390 architecture:

http://security.debian.org/pool/updat...ane-backends/libsane_1.0.7-4_s390.deb
Size/MD5 checksum: 1492610 c80c5467c124f57da1a0ec0d78be75b0
http://security.debian.org/pool/updat...backends/libsane-dev_1.0.7-4_s390.deb
Size/MD5 checksum: 4566136 68d3e765375e43ea891a5a9f39fdc40a

Sun Sparc architecture:

http://security.debian.org/pool/updat...ne-backends/libsane_1.0.7-4_sparc.deb
Size/MD5 checksum: 1584884 b84ac77275bd2910851e0f4f35d22a4d
http://security.debian.org/pool/updat...ackends/libsane-dev_1.0.7-4_sparc.deb
Size/MD5 checksum: 4770392 d64709c90f73c1f9259f96a54e5bcb45


-- Debian GNU/Linux unstable alias sid --

Fixed in version 1.0.11-1.

Provided and/or discovered by:
Alexander Hvostov, Julien Blache, and Aurelien Jarno.

Original Advisory:
http://www.debian.org/security/2003/dsa-379


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 47 views
2. Zeroboard Multiple Vulnerabilities // 43 views
3. ClamAV "cli_check_jpeg_exploit()" Denial of Service Vulnerability // 32 views
4. DAHDI "ZT_SPANCONFIG" IOCTL Privilege Escalation Vulnerability // 31 views
5. IBM Rational ClearQuest Multiple Vulnerabilities // 31 views
6. IBM Rational ClearCase Cross-Site Scripting Vulnerability // 29 views
7. bcoos "cid" SQL Injection Vulnerability // 28 views
8. Debian update for flamethrower // 28 views
9. Linksys WRT160N Cross-Site Scripting Vulnerability // 28 views
10. ASP Portal "ASPPortal.mdb" Database Disclosure Security Issue // 27 views