Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed with an attacker-controlled configuration file.
2024-03-27T06:15:10.403
2025-11-04T19:16:04.290
Modified
CVSSv3.1: 7.1 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | sane-project | sane_backends | 1.2.1 | Yes |
| Hardware | sane-project | sane_backends | - | No |