PRIMARY CATEGORY โ†’ EXPLOITS

CVE-2012-5519 ๐Ÿ’ฅ โ†’ CUPS (Common Unix Printing System)

Attack Vector ๐Ÿ—ก๏ธ โ†’ Information Disclosure due to Improper Access Control leads to LPE (Local Privilege Escalation)

Affected Versions ๐Ÿšจ โ†’ Lower than 1.6.2

Severity ๐Ÿšฉ โ†’ e.g. High 7.2/10


Description

Reference

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface


CVSSv2.0 Score

TL;DR โ†’ (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base MetricsValues
Access Vector (AV)Local
Access Complexity (AC)Low
Authentication (AU)None
Confidentiality (C)Complete
Integrity (I)Complete
Availability (A)Complete

Usage

Help Display
bash CVE-2012-5519.bash --help
Script Execution
bash CVE-2012-5519.bash --target <TARGET> --port <PORT> --file <FILE>

Zoom In


Code

Reference


References

Reference Iย ย ย ย โ€ขย ย ย ย Reference IIย ย ย ย โ€ขย ย ย ย Reference III