Samsung Linux Printer Driver SetUID Script Local Privilege Escalation Vulnerability
BID:24953
Info
Samsung Linux Printer Driver SetUID Script Local Privilege Escalation Vulnerability
| Bugtraq ID: | 24953 |
| Class: | Design Error |
| CVE: |
CVE-2007-3931 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 18 2007 12:00AM |
| Updated: | May 07 2015 05:36PM |
| Credit: | Apterium reported this issue. |
| Vulnerable: |
Samsung Linux Printer Driver 0 |
| Not Vulnerable: |
Samsung Linux Printer Driver 2.0.97 |
Discussion
Samsung Linux Printer Driver SetUID Script Local Privilege Escalation Vulnerability
Samsung Linux Printer Driver is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to execute arbitrary code with superuser privileges. Successfully exploiting this issue will result in the complete compromise of affected computers.
Samsung Linux Printer Driver is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to execute arbitrary code with superuser privileges. Successfully exploiting this issue will result in the complete compromise of affected computers.
Exploit / POC
Samsung Linux Printer Driver SetUID Script Local Privilege Escalation Vulnerability
An attacker can exploit this issue by gaining local interactive access to an affected computer and interacting with a setuid-superuser application.
An attacker can exploit this issue by gaining local interactive access to an affected computer and interacting with a setuid-superuser application.
Solution / Fix
Samsung Linux Printer Driver SetUID Script Local Privilege Escalation Vulnerability
Solution:
The vendor has released a patch to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
The vendor has released a patch to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
References
Samsung Linux Printer Driver SetUID Script Local Privilege Escalation Vulnerability
References:
References:
- Samsung drivers changing system rights (poupoul2 )
- Samsung fixes its printer drivers (corbet)
- Samsung Homepage (Samsung)
- Samsung Linux printer driver modifies the permissions of many executables (Apterium)
- Ooo s'ouvre en root et non en user normal (hdiamant)