cups: privilege escalation for users of the CUPS SystemGroup group
Published Nov 20, 2012
7.2
HIGHCVSS 2.0
EPSS 2.13%
Description
CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.
Affected products
No data.
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 5
cups-1:1.3.7-30.el5_9.3
Fixed · RHSA-2013:0580
Red Hat Enterprise Linux 6
cups-1:1.4.2-50.el6_4.4
Fixed · RHSA-2013:0580
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | cups-1:1.3.7-30.el5_9.3 | Fixed | RHSA-2013:0580 |
| Red Hat Enterprise Linux 6 | cups-1:1.4.2-50.el6_4.4 | Fixed | RHSA-2013:0580 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the version of cups as shipped with Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this issue as having moderate security impact, a future update may address this flaw.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (31 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.13% (0.02128) | 81.27th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.13% (0.02128) | 79.47th | v5 (v2026.06.15) |
| May 31, 2026 | 7.19% (0.07193) | 91.72th | v4 (v2025.03.14) |
| May 13, 2026 | 11.38% (0.11376) | 93.63th | v4 (v2025.03.14) |
| Dec 30, 2025 | 10.23% (0.10228) | 92.89th | v4 (v2025.03.14) |
| Dec 28, 2025 | 13.55% (0.13547) | 93.99th | v4 (v2025.03.14) |
| Dec 27, 2025 | 15.09% (0.15090) | 94.39th | v4 (v2025.03.14) |
| Oct 28, 2025 | 13.82% (0.13819) | 93.98th | v4 (v2025.03.14) |
| Oct 27, 2025 | 15.29% (0.15285) | 94.34th | v4 (v2025.03.14) |
| Oct 7, 2025 | 13.82% (0.13819) | 94.04th | v4 (v2025.03.14) |
| Aug 15, 2025 | 15.29% (0.15285) | 94.34th | v4 (v2025.03.14) |
| Aug 10, 2025 | 12.97% (0.12971) | 93.77th | v4 (v2025.03.14) |
| May 4, 2025 | 15.87% (0.15874) | 94.34th | v4 (v2025.03.14) |
| Mar 30, 2025 | 13.50% (0.13503) | 93.60th | v4 (v2025.03.14) |
| Mar 29, 2025 | 19.83% (0.19828) | 92.58th | v4 (v2025.03.14) |
| Mar 28, 2025 | 13.50% (0.13503) | 93.61th | v4 (v2025.03.14) |
| Mar 27, 2025 | 19.83% (0.19828) | 94.65th | v4 (v2025.03.14) |
| Mar 20, 2025 | 16.24% (0.16240) | 94.32th | v4 (v2025.03.14) |
| Mar 19, 2025 | 19.83% (0.19828) | 94.75th | v4 (v2025.03.14) |
| Mar 17, 2025 | 16.24% (0.16240) | 94.33th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.12% (0.00124) | 48.44th | v3 (v2023.03.01) |
| Apr 17, 2024 | 0.12% (0.00119) | 45.48th | v3 (v2023.03.01) |
| Dec 14, 2023 | 0.11% (0.00110) | 43.86th | v3 (v2023.03.01) |
| Oct 10, 2023 | 0.09% (0.00089) | 37.35th | v3 (v2023.03.01) |
| Apr 14, 2023 | 0.11% (0.00110) | 42.63th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.08% (0.00077) | 31.40th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.40% (0.02395) | 81.49th | v2 (v2022.01.01) |
| Feb 13, 2023 | 2.40% (0.02395) | 80.99th | v2 (v2022.01.01) |
| Feb 3, 2023 | 26.79% (0.26792) | 97.09th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.40% (0.02395) | 79.73th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.40% (0.02395) | 58.37th | v2 (v2022.01.01) |
References (17)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=692791 x_refsource_CONFIRMExploit
- http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00003.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00006.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00010.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2013-0580.html vendor-advisoryx_refsource_REDHAT
- http://support.apple.com/kb/HT5784 x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2012/11/10/5 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/11/11/2 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/11/11/5 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/56494 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-1654-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2012-5519 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=875898 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80012 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2012-5519
- https://www.cve.org/CVERecord?id=CVE-2012-5519
Change history (0)
No recorded changes yet.