-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2020.3468
                      sane-backends regression update
                              8 October 2020

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           sane-backends
Publisher:         Debian
Operating System:  Debian GNU/Linux 9
Impact/Access:     Execute Arbitrary Code/Commands -- Remote/Unauthenticated
                   Denial of Service               -- Remote/Unauthenticated
                   Access Confidential Data        -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2020-12867 CVE-2020-12865 CVE-2020-12863
                   CVE-2020-12862  

Reference:         ESB-2020.2830
                   ESB-2020.1902

Original Bulletin: 
   https://lists.debian.org/debian-lts-announce/2020/10/msg00010.html

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian LTS Advisory DLA-2332-2                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                                     
October 07, 2020                              https://wiki.debian.org/LTS
- - -------------------------------------------------------------------------

Package        : sane-backends
Version        : 1.0.25-4.1+deb9u2
CVE ID         : CVE-2020-12862 CVE-2020-12863 CVE-2020-12865 CVE-2020-12867
Debian Bug     : 961302

A regression was introduced in DLA-2332-1, where changes in the Debian
package building process triggered a bug in the sane-backends
packages, causing missing files.

For Debian 9 stretch, this problem has been fixed in version
1.0.25-4.1+deb9u2.

We recommend that you upgrade your sane-backends packages.

For the detailed security status of sane-backends please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/sane-backends

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
- -----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEEQic8GuN/xDR88HkSj/HLbo2JBZ8FAl99q00ACgkQj/HLbo2J
BZ/c/wf/fa9XIQ9ney70ty6u/vvRHg3I41OZZj18IMLfi0wf0L0mNl+UH6q3vAt9
aCqfoP3eiSbC6qHVXbirGXaJ0w8euRiASQy6kTWZI7Sep/cNFVGYbKKsHu/22+x2
jWiLvEOY2V3kBsM7w5mGiH+9HZq0VmX9OcRXMw1gfiZ+emDWANdVhiPO3PlXQU74
XnXj9KrgymqSI3ZiEL0xdsjCS8qj5HXHVhzwa7qsJn8FwFNk5gwT+sIoWUtJcHKj
svW8OA+auPAkR9bs0vnLEN0zN25lew2Z2HbTBUP/g6+g4l0NUPHpAqvo+zmNgWsb
t3zOc42LIzhIO9LdjEcXitnI9nuoqA==
=p8ZC
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBX35X4ONLKJtyKPYoAQgbxQ//fyCPxk0WYeZJERP5850JwF3fGqCwW+ET
upoTbCAzdY8W1YWUioOs3JW3i1aSMgZbhaEdKq97fNZxrCKSvJl2m8lTbJM3Cs5H
S1aBMe3BiTBYtL57bakMql7dBP0gTPQxcGo+quresLpFfoCO4ZVlHtKQTXA7VITd
u7SQ8wTkiEOVftHCu61PfHrj5/cWy5CXE8POoTTP78Dch+4kElcuDrMfd7JpKP8Y
No4WYhf6RLlevJIu13cETHaY0HcPkeE5iMPU45Ji9lW3ctIbYBEObeQbfBSFYxj9
B3GW4nd2S07ZRUoMzIPiOX+p3uNAnYp568wYfc6y+mPSifiTefVxB1iGYCCJVuih
B4h1ewVnvzC2FEYTIVSqp4HXb6kSjtZ0mt8QE4EOPX47DlwHnKKD0VEdRxF5KWfC
tlR87Reo3FviTscdw3b09AUi3hCuOl5tcmuFBS5d+rj6jDkZo+avb4RB02bIYTIZ
WewThmLC0OLxm6GrHLNhh7hfBB+GFsgWMB8mhcAw4cgmKPlcf8tFemjWLk2iUEkZ
OCnRavClUXJZf7iWqWapw8ZCVDW15zp7nnCxDT4c7IAUeVrAk460McpTxKDE4VkL
ldTt2HeP7tT1CjC4H4gmMR4rdEDqwPXkGI1U5DIHfhHS3HouSZLBY6rpEs4qhTFx
rtc5uIIktjg=
=+1M9
-----END PGP SIGNATURE-----