Executive Summary
Summary | |
---|---|
Title | New ikiwiki packages fix information disclosure |
Informations | |||
---|---|---|---|
Name | DSA-1875 | First vendor Publication | 2009-08-31 |
Vendor | Debian | Last vendor Modification | 2009-08-31 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Josh Triplett discovered that the blacklist for potentially harmful TeX code of the teximg module of the Ikiwiki wiki compiler was incomplete, resulting in information disclosure. The old stable distribution (etch) is not affected. For the stable distribution (lenny), this problem has been fixed in version 2.53.4. For the unstable distribution (sid), this problem has been fixed in version 3.1415926. We recommend that you upgrade your ikiwiki package. |
Original Source
Url : http://www.debian.org/security/2009/dsa-1875 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:13668 | |||
Oval ID: | oval:org.mitre.oval:def:13668 | ||
Title: | DSA-1875-1 ikiwiki -- missing input sanitising | ||
Description: | Josh Triplett discovered that the blacklist for potentially harmful TeX code of the teximg module of the Ikiwiki wiki compiler was incomplete, resulting in information disclosure. The old stable distribution is not affected. For the stable distribution, this problem has been fixed in version 2.53.4. For the unstable distribution, this problem has been fixed in version 3.1415926. We recommend that you upgrade your ikiwiki package. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1875-1 CVE-2009-2944 | Version: | 7 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | ikiwiki |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:7859 | |||
Oval ID: | oval:org.mitre.oval:def:7859 | ||
Title: | DSA-1875 ikiwiki -- missing input sanitising | ||
Description: | Josh Triplett discovered that the blacklist for potentially harmful TeX code of the teximg module of the Ikiwiki wiki compiler was incomplete, resulting in information disclosure. The old stable distribution (etch) is not affected. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1875 CVE-2009-2944 | Version: | 5 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | ikiwiki |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2010-04-06 | Name : Fedora Update for ikiwiki FEDORA-2010-4933 File : nvt/gb_fedora_2010_4933_ikiwiki_fc11.nasl |
2009-09-15 | Name : Fedora Core 11 FEDORA-2009-9244 (ikiwiki) File : nvt/fcore_2009_9244.nasl |
2009-09-15 | Name : Fedora Core 10 FEDORA-2009-9254 (ikiwiki) File : nvt/fcore_2009_9254.nasl |
2009-09-15 | Name : FreeBSD Ports: ikiwiki File : nvt/freebsd_ikiwiki4.nasl |
2009-09-03 | Name : ikiwiki Teximg Plugin TeX Command Arbitrary File Disclosure Vulnerability File : nvt/gb_ikiwiki_teximg_info_disclosure_vuln.nasl |
2009-09-02 | Name : Debian Security Advisory DSA 1875-1 (ikiwiki) File : nvt/deb_1875_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
57575 | teximg Plugin for ikiwiki TEX Command Arbitrary File Local Disclosure ikiwiki contains a flaw that may lead to an unauthorized information disclosure. Â The issue is triggered when a malicious user uses unsafe Tex commands, which will disclose arbitrary files resulting in a loss of confidentiality. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-02-24 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1875.nasl - Type : ACT_GATHER_INFO |
2009-09-14 | Name : The remote Fedora host is missing a security update. File : fedora_2009-9244.nasl - Type : ACT_GATHER_INFO |
2009-09-14 | Name : The remote Fedora host is missing a security update. File : fedora_2009-9254.nasl - Type : ACT_GATHER_INFO |
2009-09-14 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_6e8f54afa07d11dea649000c2955660f.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:28:47 |
|