jvndb-2010-000059
Vulnerability from jvndb
Published
2010-12-08 18:25
Modified
2010-12-08 18:25
Severity ?
() - -
Summary
Vulnerability in Epson printer driver installer where access permissions are changed
Details
A vulnerability in printer driver installers provided by Epson cause access permissions to a certain folder on the system to be changed. When printer drivers provided by Epson are installed, the access permissions for the folder that contains program files (C:\Program Files) are changed. As a result, users that do not have permission to access that folder can gain access to that folder. According to the developer, printer drivers that were included with the product or downloaded from the developer website from the initial release of May 2010 through November 25, 2010 are affected by this vulnerability. Also, users of Windows Vista and later operating systems are not affected.
Show details on JVN DB website


{
  "@rdf:about": "https://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000059.html",
  "dc:date": "2010-12-08T18:25+09:00",
  "dcterms:issued": "2010-12-08T18:25+09:00",
  "dcterms:modified": "2010-12-08T18:25+09:00",
  "description": "A vulnerability in printer driver installers provided by Epson cause access permissions to a certain folder on the system to be changed.\r\n\r\nWhen printer drivers provided by Epson are installed, the access permissions for the folder that contains program files (C:\\Program Files) are changed. As a result, users that do not have permission to access that folder can gain access to that folder.\r\n\r\nAccording to the developer, printer drivers that were included with the product or downloaded from the developer website from the initial release of May 2010 through November 25, 2010 are affected by this vulnerability.\r\nAlso, users of Windows Vista and later operating systems are not affected.",
  "link": "https://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000059.html",
  "sec:cpe": [
    {
      "#text": "cpe:/a:epson:lp-s7100",
      "@product": "Driver for LP-S7100",
      "@vendor": "SEIKO EPSON CORPORATION",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/a:epson:lp-s9000",
      "@product": "Driver for LP-S9000",
      "@vendor": "SEIKO EPSON CORPORATION",
      "@version": "2.2"
    }
  ],
  "sec:cvss": {
    "@score": "2.1",
    "@severity": "Low",
    "@type": "Base",
    "@vector": "AV:L/AC:L/Au:N/C:N/I:P/A:N",
    "@version": "2.0"
  },
  "sec:identifier": "JVNDB-2010-000059",
  "sec:references": [
    {
      "#text": "http://jvn.jp/en/jp/JVN62736872/index.html",
      "@id": "JVN#62736872",
      "@source": "JVN"
    },
    {
      "#text": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3920",
      "@id": "CVE-2010-3920",
      "@source": "CVE"
    },
    {
      "#text": "http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3920",
      "@id": "CVE-2010-3920",
      "@source": "NVD"
    },
    {
      "#text": "http://secunia.com/advisories/42540",
      "@id": "SA42540",
      "@source": "SECUNIA"
    },
    {
      "#text": "http://osvdb.org/69678",
      "@id": "69678",
      "@source": "OSVDB"
    },
    {
      "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
      "@id": "CWE-DesignError",
      "@title": "No Mapping(CWE-DesignError)"
    }
  ],
  "title": "Vulnerability in Epson printer driver installer where access permissions are changed"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…