Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.50754
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2003:099 (sane)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to sane
announced via advisory MDKSA-2003:099.

Several vulnerabilities were discovered in the saned daemon, a part of
the sane package, which allows for a scanner to be used remotely. The
IP address of the remote host is only checked after the first
communication occurs, which causes the saned.conf restrictions to be
ignored for the first connection. As well, a connection that is
dropped early can cause Denial of Service issues due to a number of
differing factors. Finally, a lack of error checking can cause various
other unfavourable actions.

The provided packages have been patched to correct the issues. sane,
as distributed in Mandrake Linux 9.1 and higher, have versions where
the fixes were applied upstream.

Affected versions: 9.0, Corporate Server 2.1

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2003:099
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0773
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0774
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0775
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0776
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0777
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0778

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2003-0773
BugTraq ID: 8593
http://www.securityfocus.com/bid/8593
BugTraq ID: 8595
http://www.securityfocus.com/bid/8595
Debian Security Information: DSA-379 (Google Search)
http://www.debian.org/security/2003/dsa-379
http://www.mandriva.com/security/advisories?name=MDKSA-2003:099
http://www.redhat.com/support/errata/RHSA-2003-278.html
http://www.redhat.com/support/errata/RHSA-2003-285.html
SCO Security Bulletin: CSSA-2004-005.0
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt
SuSE Security Announcement: SuSE-SA:2003:046 (Google Search)
http://www.novell.com/linux/security/advisories/2003_046_sane.html
Common Vulnerability Exposure (CVE) ID: CVE-2003-0774
Common Vulnerability Exposure (CVE) ID: CVE-2003-0775
BugTraq ID: 8600
http://www.securityfocus.com/bid/8600
Common Vulnerability Exposure (CVE) ID: CVE-2003-0776
Common Vulnerability Exposure (CVE) ID: CVE-2003-0777
BugTraq ID: 8597
http://www.securityfocus.com/bid/8597
Common Vulnerability Exposure (CVE) ID: CVE-2003-0778
BugTraq ID: 8596
http://www.securityfocus.com/bid/8596
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.