PT-2007-5151 · Samsung · Samsung Scx-4200 Driver
Hdiamantle
+1
·
Publicado
2007-07-21
·
Atualizado
2008-11-15
·
CVE-2007-3931
CVSS v2.0
4.4
Média
| Vetor | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Samsung SCX-4200 Driver version 2.00.95
Description:
The issue allows local users to gain privileges due to the
wrap setuid third party application function in the installation script adding setuid permissions to third-party applications such as xsane and xscanimage.Recommendations:
For Samsung SCX-4200 Driver version 2.00.95, consider removing setuid permissions from third-party applications to prevent privilege escalation until a proper fix is available. As a temporary workaround, restrict access to the
wrap setuid third party application function to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Samsung Scx-4200 Driver