Secunia Logo
 
Mandrake update for SANE
Secunia Advisory: SA9984
Release Date: 2003-10-10
Popularity: 6,433 views

Critical:
Less critical
Impact: DoS
Where: From local network
Solution Status: Vendor Patch

OS:Mandrake Corporate Server 2.x
Mandrake Linux 9.x

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2003-0773
CVE-2003-0774
CVE-2003-0775
CVE-2003-0776
CVE-2003-0777
CVE-2003-0778


Description:
MandrakeSoft has issued updated packages for sane. These fix several vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerabilities are caused due to various errors that all can be exploited to either crash the service or cause it to consume an excessive amount of memory resources.

Successful exploitation requires that saned is running but the malicious system does not have to be listed in "saned.conf".

Solution:
Upgrade automatically using MandrakeUpdate or manually by downloading the updated packages from one of MandrakeSoft's FTP server mirrors:

http://www.mandrakesecure.net/en/ftp.php


Updated packages:

-- Corporate Server 2.1 --

2de5d3fdcefdbb4ac3e838ceefb8400c corporate/2.1/RPMS/libsane1-1.0.9-3.3.90mdk.i586.rpm
835aadcbd8e68c75c8c9724dd76db8ca corporate/2.1/RPMS/libsane1-devel-1.0.9-3.3.90mdk.i586.rpm
4a51bd0457b350551384c2fd99df6386 corporate/2.1/RPMS/sane-backends-1.0.9-3.3.90mdk.i586.rpm
94003e813ce9ff8b85d58207bf4a7d0d corporate/2.1/SRPMS/sane-1.0.9-3.3.90mdk.src.rpm

x86_64:
d7b88780c7bca2bba5397a5015fbf3eb x86_64/corporate/2.1/RPMS/libsane1-1.0.9-3.3.90mdk.x86_64.rpm
c5829ec4e65696faf8c61749bbd28019 x86_64/corporate/2.1/RPMS/libsane1-devel-1.0.9-3.3.90mdk.x86_64.rpm
0dabd1912470608718c302c69292565c x86_64/corporate/2.1/RPMS/sane-backends-1.0.9-3.3.90mdk.x86_64.rpm
94003e813ce9ff8b85d58207bf4a7d0d x86_64/corporate/2.1/SRPMS/sane-1.0.9-3.3.90mdk.src.rpm


-- Mandrake Linux 9.0 --

2de5d3fdcefdbb4ac3e838ceefb8400c 9.0/RPMS/libsane1-1.0.9-3.3.90mdk.i586.rpm
835aadcbd8e68c75c8c9724dd76db8ca 9.0/RPMS/libsane1-devel-1.0.9-3.3.90mdk.i586.rpm
4a51bd0457b350551384c2fd99df6386 9.0/RPMS/sane-backends-1.0.9-3.3.90mdk.i586.rpm
94003e813ce9ff8b85d58207bf4a7d0d 9.0/SRPMS/sane-1.0.9-3.3.90mdk.src.rpm

Original Advisory:
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:099


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 67 views
2. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 34 views
3. ClamAV "cli_check_jpeg_exploit()" Denial of Service Vulnerability // 31 views
4. VLC Media Player Real Demuxer Integer Overflow Vulnerability // 28 views
5. SquirrelMail Malformed HTML Mail Message Script Insertion // 27 views
6. mvnForum Unspecified Cross-Site Scripting and Request Forgery // 26 views
7. Kolab Server ClamAV Multiple Vulnerabilities // 24 views
8. VMware ESX / ESXi Virtual Hardware Memory Corruption Vulnerability // 24 views
9. Debian update for awstats // 21 views
10. VMware ESX Server update for bzip2 // 21 views