SUSE-SU-2020:3125-1
Dashboard / Vulnerabilities / SUSE-SU-2020:3125-1
SUSE-SU-2020:3125-1
Summary: Security update for sane-backends
Details: This update for sane-backends fixes the following issues: - sane-backends version upgrade to 1.0.31: * sane-backends version upgrade to 1.0.30 fixes memory corruption bugs CVE-2020-12861, CVE-2020-12862, CVE-2020-12863, CVE-2020-12864, CVE-2020-12865, CVE-2020-12866, CVE-2020-12867 (bsc#1172524) * sane-backends version upgrade to 1.0.31 to further improve hardware enablement for scanner devices (jsc#SLE-15561 and jsc#SLE-15560 with jsc#ECO-2418) * The new escl backend cannot be provided for SLE12 because it requires more additional software (avahi-client, libcurl, and libpoppler-glib-devel) where in particular for libcurl the one that is in SLE12 (via libcurl-devel-7.37.0) is likely too old because with that building the escl backend fails with 'escl/escl.c:1267:34: error: 'CURLOPT_UNIX_SOCKET_PATH' undeclared curl_easy_setopt(handle, CURLOPT_UNIX_SOCKET_PATH'
References: https://www.suse.com/support/update/announcement/2020/suse-su-20203125-1/, https://bugzilla.suse.com/1172524, https://www.suse.com/security/cve/CVE-2017-6318, https://www.suse.com/security/cve/CVE-2020-12861, https://www.suse.com/security/cve/CVE-2020-12862, https://www.suse.com/security/cve/CVE-2020-12863, https://www.suse.com/security/cve/CVE-2020-12864, https://www.suse.com/security/cve/CVE-2020-12865, https://www.suse.com/security/cve/CVE-2020-12866, https://www.suse.com/security/cve/CVE-2020-12867
Affected packages
Package
Name: sane-backends
Purl: pkg:rpm/suse/sane-backends&distro=HPE%20Helion%20OpenStack%208
Affected ranges
Type: ECOSYSTEM
Events:
