« Volver al listado

CVE-2012-4510

Estado: ModificadaMedia (5.8)—

cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attackers to read or overwrite sensitive files using CUPS resources.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-4510",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-11-20T00:55:01.057",
  "references": [
    {
      "url": "http://www.debian.org/security/2012/dsa-2562",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2013:069",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/10/12/2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.debian.org/security/2012/dsa-2562",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2013:069",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/10/12/2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attackers to read or overwrite sensitive files using CUPS resources."
    },
    {
      "lang": "es",
      "value": "cups-pk-helper antes de v0.2.3 no trata correctamente las llamadas a funciones (1) cupsGetFile y (2) cupsPutFile, lo que permite a atacantes remotos asistidos por el usuario leer o sobrescribir archivos confidenciales utilizando recursos CUPS."
    }
  ],
  "lastModified": "2026-06-16T23:45:14.017",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cups-pk-helper_project:cups-pk-helper:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D47BA3F7-6CBC-4F27-9328-616D28633167",
              "versionEndIncluding": "0.2.2"
            },
            {
              "criteria": "cpe:2.3:a:cups-pk-helper_project:cups-pk-helper:0.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EE62B0C-B4E2-4389-861F-8ACCAAE246DB"
            },
            {
              "criteria": "cpe:2.3:a:cups-pk-helper_project:cups-pk-helper:0.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83572DA5-8545-4E52-B871-70FA5F14104D"
            },
            {
              "criteria": "cpe:2.3:a:cups-pk-helper_project:cups-pk-helper:0.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "345E9742-16E9-46D7-A47D-3DD8C0E9D7DF"
            },
            {
              "criteria": "cpe:2.3:a:cups-pk-helper_project:cups-pk-helper:0.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F188997-C3C6-4171-A152-B5A336C7E0F4"
            },
            {
              "criteria": "cpe:2.3:a:cups-pk-helper_project:cups-pk-helper:0.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D823D13-A6CA-4F2C-9265-3DF56D9EC352"
            },
            {
              "criteria": "cpe:2.3:a:cups-pk-helper_project:cups-pk-helper:0.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DBBAFB6C-3A80-4A4B-82BE-5014B93BC85A"
            },
            {
              "criteria": "cpe:2.3:a:cups-pk-helper_project:cups-pk-helper:0.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E00CDE1F-0E65-4C06-9303-277C0F1DE117"
            },
            {
              "criteria": "cpe:2.3:a:cups-pk-helper_project:cups-pk-helper:0.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E476C56E-C43C-4AFC-AD6F-BB6723F183DA"
            },
            {
              "criteria": "cpe:2.3:a:cups-pk-helper_project:cups-pk-helper:0.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0EE45D7-99BE-4D62-8C91-DCA304C72716"
            },
            {
              "criteria": "cpe:2.3:a:cups-pk-helper_project:cups-pk-helper:0.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D142AAA-7B13-4DAD-BA70-86AA0C2B46AB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}