Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SANE Internal Wire Memory Disclosure Vulnerability

SANE is prone to a vulnerability that could expose sensitive information. This could be an issue if saned is running as a service, through a super-server such as inetd or xinetd.

When a connection drop is undetected, access to an internal buffer will escape the bounds of the memory allocated for the buffer. Prior to a segmentation fault, random memory adjacent to the allocated buffer will be read, potentially exposing sensitive memory. saned will also crash as a side-effect, but will be restarted by the super-server.

This issue could potentially be exploited to execute arbitrary code if memory can be corrupted with user-supplied input, though this has not been confirmed.







 

Privacy Statement
Copyright 2008, SecurityFocus