CVE-2012-1586 is a local information disclosure vulnerability affecting mount.cifs in cifs-utils 2.6, including Debian cifs-utils. A local attacker can determine the existence of arbitrary files or directories by observing error messages generated when providing a file path as the second argument. This vulnerability has a low severity CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), indicating local access and low attack complexity are required, with only a partial impact on confidentiality. While there is an ExploitDB entry (EDB-18783) demonstrating arbitrary root file identification, there is no evidence of active exploitation, Metasploit or Nuclei modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6CPE matchmatch criteria | cpe:2.3:a:debian:cifs-utils:2.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.