Permissions, Privileges, and Access Controls in CUPS - CVE-2012-5519

 

Permissions, Privileges, and Access Controls in CUPS - CVE-2012-5519

Published: November 20, 2012 / Updated: June 15, 2023


Vulnerability identifier: #VU43321
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-5519
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.


Affected software

CUPS
Amazon Linux AMI
Gentoo Linux
SUSE Linux

How to mitigate CVE-2012-5519

Install update from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins