2024-12-08 03:06:42 +00:00

552 lines
20 KiB
JSON

{
"id": "CVE-2009-2944",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-08-31T20:30:00.920",
"lastModified": "2024-11-21T01:06:07.210",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands."
},
{
"lang": "es",
"value": "Vulnerabilidad de lista negra incompleta en el plugin teximg en ikiwiki anterior a v3.1415926 y v2.x anterior a v2.53.4, permite a atacantes dependientes de contexto leer archivos de su elecci\u00f3n a trav\u00e9s de comando TeX manipulados."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"baseScore": 5.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:*:*:*:*:*:*:*:*",
"versionEndIncluding": "3.141592",
"matchCriteriaId": "5A161EE7-4B7F-43C2-ADE3-0F3FD7A333EB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "196439CC-B5BE-4016-B6CF-B8308002D61E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.00:*:*:*:*:*:*:*",
"matchCriteriaId": "0AE568DE-413C-4EF7-96C6-AF2D47EB36BB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "20FFAE6B-9EBD-461A-AF5C-BB00EA2A652F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.2:*:*:*:*:*:*:*",
"matchCriteriaId": "7C064545-5C87-4CC5-A9FA-379A9F4ED0A2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.3:*:*:*:*:*:*:*",
"matchCriteriaId": "729BA91F-625A-4734-814D-EADE78A42CEC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.4:*:*:*:*:*:*:*",
"matchCriteriaId": "025BA9CF-1F77-4BC1-A884-3E49B23BB668"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.5:*:*:*:*:*:*:*",
"matchCriteriaId": "C3120790-F2E2-4780-8022-B88EB326C8EC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.6:*:*:*:*:*:*:*",
"matchCriteriaId": "DF180F3A-2B55-4555-9A3B-D8C12CB52CF2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.6.1:*:*:*:*:*:*:*",
"matchCriteriaId": "BF68A8E1-96D7-49A5-B844-9FE7A0FE9631"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.7:*:*:*:*:*:*:*",
"matchCriteriaId": "E1152479-FAAA-4AF5-85A8-9454C48CE087"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.8:*:*:*:*:*:*:*",
"matchCriteriaId": "4490706B-50FF-4126-8EB8-4F4AFDE5B2D0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.9:*:*:*:*:*:*:*",
"matchCriteriaId": "70DD7148-E3ED-4726-A7B7-E4DEB6978DAF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.10:*:*:*:*:*:*:*",
"matchCriteriaId": "350315D5-C124-430D-BD7C-9EE5C3F4D957"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.11:*:*:*:*:*:*:*",
"matchCriteriaId": "8CA658C7-2D79-4A8D-977E-D7F4640CEAFF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.12:*:*:*:*:*:*:*",
"matchCriteriaId": "8892C63F-297A-4D7A-8F63-B15BAE578645"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.13:*:*:*:*:*:*:*",
"matchCriteriaId": "0E83FBBB-0837-41EE-A56A-C837FAE6394C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.14:*:*:*:*:*:*:*",
"matchCriteriaId": "E14AF144-D023-4FF1-B6B6-FF3E74D61F8E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.15:*:*:*:*:*:*:*",
"matchCriteriaId": "2FDE3606-418B-4E76-97F8-655CE1679857"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.16:*:*:*:*:*:*:*",
"matchCriteriaId": "0F6877A1-D793-48A7-9187-63EA568EC854"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.17:*:*:*:*:*:*:*",
"matchCriteriaId": "739EB847-21B4-4728-9F38-3925893A37A1"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.18:*:*:*:*:*:*:*",
"matchCriteriaId": "FA1630A6-8578-4B0A-9F12-549EE0C42E8B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.19:*:*:*:*:*:*:*",
"matchCriteriaId": "15FE7BEB-A9E9-476A-ABDF-663A8F69BA7B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.20:*:*:*:*:*:*:*",
"matchCriteriaId": "10E53E42-F691-4237-AAC1-A93E35EADD36"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.30:*:*:*:*:*:*:*",
"matchCriteriaId": "6994F418-61A4-4CB5-94FA-C7DC7A31BBB5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.31:*:*:*:*:*:*:*",
"matchCriteriaId": "356A3B66-637B-4429-A201-EAB0A8FD9DB5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.31.1:*:*:*:*:*:*:*",
"matchCriteriaId": "11BC2505-E5EF-4CA4-B747-F74F20BFDCE5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.31.2:*:*:*:*:*:*:*",
"matchCriteriaId": "6CDB27DC-1B2B-4893-AFC7-71535919567B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.31.3:*:*:*:*:*:*:*",
"matchCriteriaId": "18275BA3-A5D0-410B-9D90-B8DBDB486849"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.40:*:*:*:*:*:*:*",
"matchCriteriaId": "06E20D04-ADEA-4773-843A-2D6BB0FC5591"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.41:*:*:*:*:*:*:*",
"matchCriteriaId": "C76D329C-975F-4180-9102-2CAA24230C6A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.42:*:*:*:*:*:*:*",
"matchCriteriaId": "86A6C38C-6B71-4A83-B280-C1195D668DDF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.43:*:*:*:*:*:*:*",
"matchCriteriaId": "0AB24A6A-D1D2-4200-ACF6-93F20AA2CEE2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.44:*:*:*:*:*:*:*",
"matchCriteriaId": "3B998D73-576D-4942-A164-8898437815DA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.45:*:*:*:*:*:*:*",
"matchCriteriaId": "69FBED8F-C567-4366-97E7-E5CF6A9BC479"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.46:*:*:*:*:*:*:*",
"matchCriteriaId": "01494227-D431-4F2B-8174-25A5C2CBC3FB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.47:*:*:*:*:*:*:*",
"matchCriteriaId": "C26EFAF6-5DE3-4562-A831-DE9CCD40B31E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.48:*:*:*:*:*:*:*",
"matchCriteriaId": "553F2BF0-0375-406F-9F6D-33E49543BC4A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.49:*:*:*:*:*:*:*",
"matchCriteriaId": "06FBD3B4-99E3-4ED5-A49F-8747C26962BE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.50:*:*:*:*:*:*:*",
"matchCriteriaId": "4888637D-EBA4-4DD3-9EE9-ABA9D26799AD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.51:*:*:*:*:*:*:*",
"matchCriteriaId": "5B6F140A-2391-4663-B680-8E58FD315C4C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.52:*:*:*:*:*:*:*",
"matchCriteriaId": "29DF1E0B-250C-47C1-BC76-4F9EE90AB836"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.53:*:*:*:*:*:*:*",
"matchCriteriaId": "82F41174-0E9C-4A09-BAEB-D75595181334"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.54:*:*:*:*:*:*:*",
"matchCriteriaId": "744A8DB6-3FD4-4891-B623-6E4AE0518867"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.55:*:*:*:*:*:*:*",
"matchCriteriaId": "90056C13-CF77-4BE1-A9CE-C8811ABA29C9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.56:*:*:*:*:*:*:*",
"matchCriteriaId": "E013025D-F390-4206-8BE6-42F5F6DBCDFB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.60:*:*:*:*:*:*:*",
"matchCriteriaId": "1C334708-7565-4E30-BEC5-75CB91B13645"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.61:*:*:*:*:*:*:*",
"matchCriteriaId": "C2E0BDA8-8EBE-4D8F-B65E-6D22C89A7F54"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.62:*:*:*:*:*:*:*",
"matchCriteriaId": "502FAEEA-7E31-49A2-9F1B-79CB5D7A094B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.62.1:*:*:*:*:*:*:*",
"matchCriteriaId": "325CDDEF-2C66-4B9B-9B70-B4FA5D619F33"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.63:*:*:*:*:*:*:*",
"matchCriteriaId": "E0B7CA1D-C4CA-45CD-B6AB-48E3CA289714"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.64:*:*:*:*:*:*:*",
"matchCriteriaId": "E3BC2691-C9B1-46C1-A3DD-D232BEB25B2B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.65:*:*:*:*:*:*:*",
"matchCriteriaId": "8CE00B3B-220C-4FD0-83FC-CB235E2C91D9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.66:*:*:*:*:*:*:*",
"matchCriteriaId": "984B8C95-0B58-4585-9EC8-393563DA7851"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.67:*:*:*:*:*:*:*",
"matchCriteriaId": "3261F3F5-BBAC-407A-BD0B-159F295D6B86"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.68:*:*:*:*:*:*:*",
"matchCriteriaId": "C5FFEB95-74D2-4EF9-9816-279546590319"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.69:*:*:*:*:*:*:*",
"matchCriteriaId": "EA175F1E-3D1F-42B1-9FA5-66187EB89670"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.70:*:*:*:*:*:*:*",
"matchCriteriaId": "4D6EA187-821B-4673-9581-FD1A877E6CD5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.71:*:*:*:*:*:*:*",
"matchCriteriaId": "EAE832BA-23B5-4D10-866D-10EB86217795"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:2.72:*:*:*:*:*:*:*",
"matchCriteriaId": "EA08E303-A084-4CAF-AA7D-39E3289B6514"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.0:*:*:*:*:*:*:*",
"matchCriteriaId": "7CF7F5FD-27CB-4E7E-AF50-EAAB20DAD289"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.00:*:*:*:*:*:*:*",
"matchCriteriaId": "02ADB4DC-4FA7-4696-BE15-4038AA7C8440"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.01:*:*:*:*:*:*:*",
"matchCriteriaId": "CCA76343-5D08-4E79-8E83-29799E8BF9C6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.02:*:*:*:*:*:*:*",
"matchCriteriaId": "110383CC-7DAB-4FC7-9898-92AF1CB76585"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.03:*:*:*:*:*:*:*",
"matchCriteriaId": "CB47B7AD-40A2-466F-AF26-92DB4BF9EDCB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.04:*:*:*:*:*:*:*",
"matchCriteriaId": "4560DD73-D1A2-46D9-A3F7-BAC5A294B91B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.06:*:*:*:*:*:*:*",
"matchCriteriaId": "27D8EE30-BFBB-45C6-8B27-012E17CA3C48"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.07:*:*:*:*:*:*:*",
"matchCriteriaId": "7374FCDB-55E7-48AC-8E38-51C20500BBE6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.08:*:*:*:*:*:*:*",
"matchCriteriaId": "03FA5A43-6317-4510-BC00-7BCF3DB4F502"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.09:*:*:*:*:*:*:*",
"matchCriteriaId": "695759BE-8539-496A-AABD-2F56ACFDA0FD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.10:*:*:*:*:*:*:*",
"matchCriteriaId": "0566B074-7F01-4482-8F26-F08EDD4F0B9A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.11:*:*:*:*:*:*:*",
"matchCriteriaId": "9A3D2C53-A15F-4FEF-A56B-A4A00C24DF39"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.12:*:*:*:*:*:*:*",
"matchCriteriaId": "B8F89322-85B0-4C8B-AB60-4577FB914D4F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.13:*:*:*:*:*:*:*",
"matchCriteriaId": "5B55BCD8-E214-4C75-86F7-247ECBEAFF1B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.14:*:*:*:*:*:*:*",
"matchCriteriaId": "B19DCEDD-AC25-48F2-B0D9-F35C67AA3A24"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.141:*:*:*:*:*:*:*",
"matchCriteriaId": "9DDE6204-5CC9-4867-BD9E-9C999C1E6D6F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.1415:*:*:*:*:*:*:*",
"matchCriteriaId": "29453740-F182-4BD1-ADD8-BF3F37D2D4DB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ikiwiki:ikiwiki:3.14159:*:*:*:*:*:*:*",
"matchCriteriaId": "A6FA5E6A-F504-43DC-8021-1BE35FB25269"
}
]
}
]
}
],
"references": [
{
"url": "http://ikiwiki.info/security/#index35h2",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://osvdb.org/57575",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/36516",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/36539",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2009/dsa-1875",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/36181",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.vupen.com/english/advisories/2009/2475",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52922",
"source": "cve@mitre.org"
},
{
"url": "http://ikiwiki.info/security/#index35h2",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://osvdb.org/57575",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/36516",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/36539",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2009/dsa-1875",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/36181",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch"
]
},
{
"url": "http://www.vupen.com/english/advisories/2009/2475",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52922",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}