CVE-2012-5519

Severity
7.2HIGH
EPSS
10.2%
top 6.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 20
Latest updateMay 17

Description

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

Debiancups< 1.5.3-2.7+3
NVDapple/cups1.4.4

🔴Vulnerability Details

3
GHSA
GHSA-ccjj-h3mm-j4rr: CUPS 12022-05-17
OSV
CVE-2012-5519: CUPS 12012-11-20
CVEList
CVE-2012-5519: CUPS 12012-11-20

📋Vendor Advisories

3
Ubuntu
CUPS vulnerability2012-12-05
Red Hat
cups: privilege escalation for users of the CUPS SystemGroup group2012-11-08
Debian
CVE-2012-5519: cups - CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux...2012

💬Community

2
Bugzilla
CVE-2012-5519 cups: Privilege escalation due improper drop of privileges for the members (different than root) of SystemGroup group [fedora-all]2012-11-12
Bugzilla
CVE-2012-5519 cups: privilege escalation for users of the CUPS SystemGroup group2012-11-12
CVE-2012-5519 (HIGH CVSS 7.2) | CUPS 1.4.4 | cvebase.io