Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-5519

Опубликовано: 08 нояб. 2012
Источник: redhat
CVSS2: 7.4
EPSS Средний

Описание

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.

Отчет

This issue affects the version of cups as shipped with Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this issue as having moderate security impact, a future update may address this flaw.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=875898cups: privilege escalation for users of the CUPS SystemGroup group

EPSS

Процентиль: 94%
0.15285
Средний

7.4 High

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.

nvd
почти 13 лет назад

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.

debian
почти 13 лет назад

CUPS 1.4.4, when running in certain Linux distributions such as Debian ...

github
больше 3 лет назад

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.

oracle-oval
больше 12 лет назад

ELSA-2013-0580: cups security update (MODERATE)

EPSS

Процентиль: 94%
0.15285
Средний

7.4 High

CVSS2