Bugzilla – Bug 1222062
VUL-1: CVE-2023-46052: sane-backends: heap out of bounds write in init_options() from backend/test.c via a long init_mode string in a configuration file
Last modified: 2024-03-27 12:15:02 UTC
Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed with an attacker-controlled configuration file. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-46052 https://www.cve.org/CVERecord?id=CVE-2023-46052 http://seclists.org/fulldisclosure/2024/Jan/69 https://gitlab.com/sane-project/backends/-/issues/709