CVE-2023-46052

high

Description

Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed with an attacker-controlled configuration file.

References

https://gitlab.com/sane-project/backends/-/issues/709

http://seclists.org/fulldisclosure/2024/Jan/69

http://packetstormsecurity.com/files/176823/sane-1.2.1-Buffer-Overflow.html

Details

Source: Mitre, NVD

Published: 2024-03-27

Updated: 2025-11-04

Risk Information

CVSS v2

Base Score: 6.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

Severity: High

EPSS

EPSS: 0.00083