Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-5519

Опубликовано: 20 нояб. 2012
Источник: nvd
CVSS2: 7.2
EPSS Средний

Описание

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apple:cups:1.4.4:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.15285
Средний

7.2 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
почти 13 лет назад

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.

redhat
почти 13 лет назад

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.

debian
почти 13 лет назад

CUPS 1.4.4, when running in certain Linux distributions such as Debian ...

github
больше 3 лет назад

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.

oracle-oval
больше 12 лет назад

ELSA-2013-0580: cups security update (MODERATE)

EPSS

Процентиль: 94%
0.15285
Средний

7.2 High

CVSS2

Дефекты

CWE-264