Vulnerabilities > CVE-2007-3931 - Local Privilege Escalation vulnerability in Samsung Scx-4200 Driver 2.00.95

047910
CVSS 4.4 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
samsung

Summary

The wrap_setuid_third_party_application function in the installation script for the Samsung SCX-4200 Driver 2.00.95 adds setuid permissions to third party applications such as xsane and xscanimage, which allows local users to gain privileges.

Vulnerable Configurations

Part Description Count
Application
Samsung
1