An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controlled configuration file.
2024-03-27T05:15:47.500
2025-11-04T19:16:03.610
Modified
CVSSv3.1: 7.3 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | sane-project | sane_backends | 1.2.1 | Yes |
| Hardware | sane-project | sane_backends | - | No |