{ "id": "CVE-2009-2944", "sourceIdentifier": "cve@mitre.org", "published": "2009-08-31T20:30:00.920", "lastModified": "2024-11-21T01:06:07.210", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands." }, { "lang": "es", "value": "Vulnerabilidad de lista negra incompleta en el plugin teximg en ikiwiki anterior a v3.1415926 y v2.x anterior a v2.53.4, permite a atacantes dependientes de contexto leer archivos de su elecci\u00f3n a trav\u00e9s de comando TeX manipulados." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "baseScore": 5.0, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:*:*:*:*:*:*:*:*", "versionEndIncluding": "3.141592", "matchCriteriaId": "5A161EE7-4B7F-43C2-ADE3-0F3FD7A333EB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.0:*:*:*:*:*:*:*", "matchCriteriaId": "196439CC-B5BE-4016-B6CF-B8308002D61E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.00:*:*:*:*:*:*:*", "matchCriteriaId": "0AE568DE-413C-4EF7-96C6-AF2D47EB36BB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.1:*:*:*:*:*:*:*", "matchCriteriaId": "20FFAE6B-9EBD-461A-AF5C-BB00EA2A652F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.2:*:*:*:*:*:*:*", "matchCriteriaId": "7C064545-5C87-4CC5-A9FA-379A9F4ED0A2" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.3:*:*:*:*:*:*:*", "matchCriteriaId": "729BA91F-625A-4734-814D-EADE78A42CEC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.4:*:*:*:*:*:*:*", "matchCriteriaId": "025BA9CF-1F77-4BC1-A884-3E49B23BB668" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.5:*:*:*:*:*:*:*", "matchCriteriaId": "C3120790-F2E2-4780-8022-B88EB326C8EC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.6:*:*:*:*:*:*:*", "matchCriteriaId": "DF180F3A-2B55-4555-9A3B-D8C12CB52CF2" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.6.1:*:*:*:*:*:*:*", "matchCriteriaId": "BF68A8E1-96D7-49A5-B844-9FE7A0FE9631" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.7:*:*:*:*:*:*:*", "matchCriteriaId": "E1152479-FAAA-4AF5-85A8-9454C48CE087" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.8:*:*:*:*:*:*:*", "matchCriteriaId": "4490706B-50FF-4126-8EB8-4F4AFDE5B2D0" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.9:*:*:*:*:*:*:*", "matchCriteriaId": "70DD7148-E3ED-4726-A7B7-E4DEB6978DAF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.10:*:*:*:*:*:*:*", "matchCriteriaId": "350315D5-C124-430D-BD7C-9EE5C3F4D957" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.11:*:*:*:*:*:*:*", "matchCriteriaId": "8CA658C7-2D79-4A8D-977E-D7F4640CEAFF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.12:*:*:*:*:*:*:*", "matchCriteriaId": "8892C63F-297A-4D7A-8F63-B15BAE578645" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.13:*:*:*:*:*:*:*", "matchCriteriaId": "0E83FBBB-0837-41EE-A56A-C837FAE6394C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.14:*:*:*:*:*:*:*", "matchCriteriaId": "E14AF144-D023-4FF1-B6B6-FF3E74D61F8E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.15:*:*:*:*:*:*:*", "matchCriteriaId": "2FDE3606-418B-4E76-97F8-655CE1679857" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.16:*:*:*:*:*:*:*", "matchCriteriaId": "0F6877A1-D793-48A7-9187-63EA568EC854" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.17:*:*:*:*:*:*:*", "matchCriteriaId": "739EB847-21B4-4728-9F38-3925893A37A1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.18:*:*:*:*:*:*:*", "matchCriteriaId": "FA1630A6-8578-4B0A-9F12-549EE0C42E8B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.19:*:*:*:*:*:*:*", "matchCriteriaId": "15FE7BEB-A9E9-476A-ABDF-663A8F69BA7B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.20:*:*:*:*:*:*:*", "matchCriteriaId": "10E53E42-F691-4237-AAC1-A93E35EADD36" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.30:*:*:*:*:*:*:*", "matchCriteriaId": "6994F418-61A4-4CB5-94FA-C7DC7A31BBB5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.31:*:*:*:*:*:*:*", "matchCriteriaId": "356A3B66-637B-4429-A201-EAB0A8FD9DB5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.31.1:*:*:*:*:*:*:*", "matchCriteriaId": "11BC2505-E5EF-4CA4-B747-F74F20BFDCE5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.31.2:*:*:*:*:*:*:*", "matchCriteriaId": "6CDB27DC-1B2B-4893-AFC7-71535919567B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.31.3:*:*:*:*:*:*:*", "matchCriteriaId": "18275BA3-A5D0-410B-9D90-B8DBDB486849" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.40:*:*:*:*:*:*:*", "matchCriteriaId": "06E20D04-ADEA-4773-843A-2D6BB0FC5591" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.41:*:*:*:*:*:*:*", "matchCriteriaId": "C76D329C-975F-4180-9102-2CAA24230C6A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.42:*:*:*:*:*:*:*", "matchCriteriaId": "86A6C38C-6B71-4A83-B280-C1195D668DDF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.43:*:*:*:*:*:*:*", "matchCriteriaId": "0AB24A6A-D1D2-4200-ACF6-93F20AA2CEE2" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.44:*:*:*:*:*:*:*", "matchCriteriaId": "3B998D73-576D-4942-A164-8898437815DA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.45:*:*:*:*:*:*:*", "matchCriteriaId": "69FBED8F-C567-4366-97E7-E5CF6A9BC479" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.46:*:*:*:*:*:*:*", "matchCriteriaId": "01494227-D431-4F2B-8174-25A5C2CBC3FB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.47:*:*:*:*:*:*:*", "matchCriteriaId": "C26EFAF6-5DE3-4562-A831-DE9CCD40B31E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.48:*:*:*:*:*:*:*", "matchCriteriaId": "553F2BF0-0375-406F-9F6D-33E49543BC4A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.49:*:*:*:*:*:*:*", "matchCriteriaId": "06FBD3B4-99E3-4ED5-A49F-8747C26962BE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.50:*:*:*:*:*:*:*", "matchCriteriaId": "4888637D-EBA4-4DD3-9EE9-ABA9D26799AD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.51:*:*:*:*:*:*:*", "matchCriteriaId": "5B6F140A-2391-4663-B680-8E58FD315C4C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.52:*:*:*:*:*:*:*", "matchCriteriaId": "29DF1E0B-250C-47C1-BC76-4F9EE90AB836" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.53:*:*:*:*:*:*:*", "matchCriteriaId": "82F41174-0E9C-4A09-BAEB-D75595181334" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.54:*:*:*:*:*:*:*", "matchCriteriaId": "744A8DB6-3FD4-4891-B623-6E4AE0518867" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.55:*:*:*:*:*:*:*", "matchCriteriaId": "90056C13-CF77-4BE1-A9CE-C8811ABA29C9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.56:*:*:*:*:*:*:*", "matchCriteriaId": "E013025D-F390-4206-8BE6-42F5F6DBCDFB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.60:*:*:*:*:*:*:*", "matchCriteriaId": "1C334708-7565-4E30-BEC5-75CB91B13645" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.61:*:*:*:*:*:*:*", "matchCriteriaId": "C2E0BDA8-8EBE-4D8F-B65E-6D22C89A7F54" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.62:*:*:*:*:*:*:*", "matchCriteriaId": "502FAEEA-7E31-49A2-9F1B-79CB5D7A094B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.62.1:*:*:*:*:*:*:*", "matchCriteriaId": "325CDDEF-2C66-4B9B-9B70-B4FA5D619F33" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.63:*:*:*:*:*:*:*", "matchCriteriaId": "E0B7CA1D-C4CA-45CD-B6AB-48E3CA289714" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.64:*:*:*:*:*:*:*", "matchCriteriaId": "E3BC2691-C9B1-46C1-A3DD-D232BEB25B2B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.65:*:*:*:*:*:*:*", "matchCriteriaId": "8CE00B3B-220C-4FD0-83FC-CB235E2C91D9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.66:*:*:*:*:*:*:*", "matchCriteriaId": "984B8C95-0B58-4585-9EC8-393563DA7851" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.67:*:*:*:*:*:*:*", "matchCriteriaId": "3261F3F5-BBAC-407A-BD0B-159F295D6B86" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.68:*:*:*:*:*:*:*", "matchCriteriaId": "C5FFEB95-74D2-4EF9-9816-279546590319" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.69:*:*:*:*:*:*:*", "matchCriteriaId": "EA175F1E-3D1F-42B1-9FA5-66187EB89670" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.70:*:*:*:*:*:*:*", "matchCriteriaId": "4D6EA187-821B-4673-9581-FD1A877E6CD5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.71:*:*:*:*:*:*:*", "matchCriteriaId": "EAE832BA-23B5-4D10-866D-10EB86217795" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.72:*:*:*:*:*:*:*", "matchCriteriaId": "EA08E303-A084-4CAF-AA7D-39E3289B6514" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.0:*:*:*:*:*:*:*", "matchCriteriaId": "7CF7F5FD-27CB-4E7E-AF50-EAAB20DAD289" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.00:*:*:*:*:*:*:*", "matchCriteriaId": "02ADB4DC-4FA7-4696-BE15-4038AA7C8440" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.01:*:*:*:*:*:*:*", "matchCriteriaId": "CCA76343-5D08-4E79-8E83-29799E8BF9C6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.02:*:*:*:*:*:*:*", "matchCriteriaId": "110383CC-7DAB-4FC7-9898-92AF1CB76585" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.03:*:*:*:*:*:*:*", "matchCriteriaId": "CB47B7AD-40A2-466F-AF26-92DB4BF9EDCB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.04:*:*:*:*:*:*:*", "matchCriteriaId": "4560DD73-D1A2-46D9-A3F7-BAC5A294B91B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.06:*:*:*:*:*:*:*", "matchCriteriaId": "27D8EE30-BFBB-45C6-8B27-012E17CA3C48" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.07:*:*:*:*:*:*:*", "matchCriteriaId": "7374FCDB-55E7-48AC-8E38-51C20500BBE6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.08:*:*:*:*:*:*:*", "matchCriteriaId": "03FA5A43-6317-4510-BC00-7BCF3DB4F502" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.09:*:*:*:*:*:*:*", "matchCriteriaId": "695759BE-8539-496A-AABD-2F56ACFDA0FD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.10:*:*:*:*:*:*:*", "matchCriteriaId": "0566B074-7F01-4482-8F26-F08EDD4F0B9A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.11:*:*:*:*:*:*:*", "matchCriteriaId": "9A3D2C53-A15F-4FEF-A56B-A4A00C24DF39" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.12:*:*:*:*:*:*:*", "matchCriteriaId": "B8F89322-85B0-4C8B-AB60-4577FB914D4F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.13:*:*:*:*:*:*:*", "matchCriteriaId": "5B55BCD8-E214-4C75-86F7-247ECBEAFF1B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.14:*:*:*:*:*:*:*", "matchCriteriaId": "B19DCEDD-AC25-48F2-B0D9-F35C67AA3A24" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.141:*:*:*:*:*:*:*", "matchCriteriaId": "9DDE6204-5CC9-4867-BD9E-9C999C1E6D6F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.1415:*:*:*:*:*:*:*", "matchCriteriaId": "29453740-F182-4BD1-ADD8-BF3F37D2D4DB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.14159:*:*:*:*:*:*:*", "matchCriteriaId": "A6FA5E6A-F504-43DC-8021-1BE35FB25269" } ] } ] } ], "references": [ { "url": "http://ikiwiki.info/security/#index35h2", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://osvdb.org/57575", "source": "cve@mitre.org" }, { "url": "http://secunia.com/advisories/36516", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/36539", "source": "cve@mitre.org" }, { "url": "http://www.debian.org/security/2009/dsa-1875", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/36181", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "http://www.vupen.com/english/advisories/2009/2475", "source": "cve@mitre.org", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52922", "source": "cve@mitre.org" }, { "url": "http://ikiwiki.info/security/#index35h2", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://osvdb.org/57575", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://secunia.com/advisories/36516", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/36539", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.debian.org/security/2009/dsa-1875", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.securityfocus.com/bid/36181", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch" ] }, { "url": "http://www.vupen.com/english/advisories/2009/2475", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52922", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }