CVE-2012-5519

EUVD-2012-5411
CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
Affected Products (NVD)
VendorProductVersion
applecups
1.4.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cups
bookworm
2.4.2-3+deb12u7
fixed
bookworm (security)
2.4.2-3+deb12u8
fixed
bullseye
2.3.3op2-3+deb11u8
fixed
bullseye (security)
2.3.3op2-3+deb11u9
fixed
sid
2.4.10-2
fixed
trixie
2.4.10-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cups
hardy
dne
lucid
Fixed 1.4.3-1ubuntu1.9
released
oneiric
Fixed 1.5.0-8ubuntu7.3
released
precise
Fixed 1.5.3-0ubuntu5.1
released
quantal
Fixed 1.6.1-0ubuntu11.3
released
cupsys
hardy
Fixed 1.3.7-1ubuntu3.16
released
lucid
dne
oneiric
dne
precise
dne
quantal
dne
Common Weakness Enumeration