CVE-2009-4405
published 2009-12-23CVE-2009-4405: Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) "policy checks in report results…
PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.97%
78.2th percentile
Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) "policy checks in report results when using alternate formats" or (2) a "check for the 'raw' role that is missing in docutils < 0.6."
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | trac | < trac 0.11.6-1 (sid) | trac 0.11.6-1 (sid) |
| edgewall | trac | <= 0.11.5 | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
| edgewall | trac | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Trac is vulnerable to improper policy checks and missing 'raw' role check in docutils
osv·2022-05-02
CVE-2009-4405 [HIGH] Trac is vulnerable to improper policy checks and missing 'raw' role check in docutils
Trac is vulnerable to improper policy checks and missing 'raw' role check in docutils
Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) "policy checks in report results when using alternate formats" or (2) a "check for the 'raw' role that is missing in docutils < 0.6."
GHSA
Trac is vulnerable to improper policy checks and missing 'raw' role check in docutils
ghsa·2022-05-02
CVE-2009-4405 [HIGH] Trac is vulnerable to improper policy checks and missing 'raw' role check in docutils
Trac is vulnerable to improper policy checks and missing 'raw' role check in docutils
Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) "policy checks in report results when using alternate formats" or (2) a "check for the 'raw' role that is missing in docutils < 0.6."
OSV
CVE-2009-4405: Multiple unspecified vulnerabilities in Trac before 0
osv·2009-12-23·CVSS 7.5
CVE-2009-4405 [HIGH] CVE-2009-4405: Multiple unspecified vulnerabilities in Trac before 0
Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) "policy checks in report results when using alternate formats" or (2) a "check for the 'raw' role that is missing in docutils < 0.6."
Debian
CVE-2009-4405: trac - Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact a...
vendor_debian·2009·CVSS 7.5
CVE-2009-4405 [HIGH] CVE-2009-4405: trac - Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact a...
Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) "policy checks in report results when using alternate formats" or (2) a "check for the 'raw' role that is missing in docutils < 0.6."
Scope: local
sid: resolved (fixed in 0.11.6-1)
trixie: resolved (fixed in 0.11.6-1)
Red Hat
xen: Incomplete upstream fix for CVE-2008-4405
vendor_redhat·2008-12-18·CVSS 7.2
CVE-2008-5716 [HIGH] xen: Incomplete upstream fix for CVE-2008-4405
xen: Incomplete upstream fix for CVE-2008-4405
xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue exists because of erroneous set_permissions calls in the fix for CVE-2008-4405.
Statement: Not vulnerable. This issue did not affect the versions of Xen as shipped with Red Hat Enterprise Linux 5. Security update released to address CVE-2008-4405 - RHSA-2009:0003 - contained correct patch which did not introduce this problem and resolved the original issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/37807http://secunia.com/advisories/37901http://trac.edgewall.org/browser/tags/trac-0.11.6/RELEASEhttp://www.vupen.com/english/advisories/2009/3615https://bugzilla.redhat.com/show_bug.cgi?id=542394https://exchange.xforce.ibmcloud.com/vulnerabilities/54983https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01169.htmlhttp://secunia.com/advisories/37807http://secunia.com/advisories/37901http://trac.edgewall.org/browser/tags/trac-0.11.6/RELEASEhttp://www.vupen.com/english/advisories/2009/3615https://bugzilla.redhat.com/show_bug.cgi?id=542394https://exchange.xforce.ibmcloud.com/vulnerabilities/54983https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01169.html
2009-12-23
Published