PT-2007-5151 · Samsung · Samsung Scx-4200 Driver
Hdiamantle
+1
·
Published
2007-07-21
·
Updated
2008-11-15
·
CVE-2007-3931
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Samsung SCX-4200 Driver version 2.00.95
Description:
The issue allows local users to gain privileges due to the
wrap setuid third party application function in the installation script adding setuid permissions to third-party applications such as xsane and xscanimage.Recommendations:
For Samsung SCX-4200 Driver version 2.00.95, consider removing setuid permissions from third-party applications to prevent privilege escalation until a proper fix is available. As a temporary workaround, restrict access to the
wrap setuid third party application function to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Samsung Scx-4200 Driver