CVE-2012-5519
HIGH 7.2EPSS 2.1%
CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.
- CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 2.13% chance of exploitation in the next 30 days, 81th percentile
- Published
- 2012-11-20
- Updated
- 2024-08-06
Proof-of-concept exploits (2)
- 0zvxr/CVE-2012-55199★ · 2022-06-30
- p1ckzi/CVE-2012-55199★ · 2022-06-30