PT-2007-5151 · Samsung · Samsung Scx-4200 Driver

Hdiamantle

+1

·

Published

2007-07-21

·

Updated

2008-11-15

·

CVE-2007-3931

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Samsung SCX-4200 Driver version 2.00.95
Description: The issue allows local users to gain privileges due to the wrap setuid third party application function in the installation script adding setuid permissions to third-party applications such as xsane and xscanimage.
Recommendations: For Samsung SCX-4200 Driver version 2.00.95, consider removing setuid permissions from third-party applications to prevent privilege escalation until a proper fix is available. As a temporary workaround, restrict access to the wrap setuid third party application function to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3931

Affected Products

Samsung Scx-4200 Driver