CVE-2011-4458
published 2012-06-04CVE-2011-4458: Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote…
PriorityP340medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.10%
86.1th percentile
Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-5092 and CVE-2011-5093.
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2011-4458: request-tracker4 - Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before...
vendor_debian·2011·CVSS 6.8
CVE-2011-4458 [MEDIUM] CVE-2011-4458: request-tracker4 - Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before...
Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-5092 and CVE-2011-5093.
Scope: local
bookworm: resolved (fixed in 4.0.5-3)
bullseye: resolved (fixed in 4.0.5-3)
sid: resolved (fixed in 4.0.5-3)
GHSA
GHSA-jv9v-724f-v2g6: Best Practical Solutions RT 3
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2011-5092 [MEDIUM] GHSA-jv9v-724f-v2g6: Best Practical Solutions RT 3
Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges via unspecified vectors, a different vulnerability than CVE-2011-4458 and CVE-2011-5093.
GHSA
GHSA-397q-whxp-h2p3: Best Practical Solutions RT 3
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2011-4458 [HIGH] CWE-94 GHSA-397q-whxp-h2p3: Best Practical Solutions RT 3
Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-5092 and CVE-2011-5093.
GHSA
GHSA-3hp8-xj8q-7jfq: Best Practical Solutions RT 4
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2011-5093 [MEDIUM] GHSA-3hp8-xj8q-7jfq: Best Practical Solutions RT 4
Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated users to bypass intended access restrictions and execute arbitrary code by leveraging access to a privileged account, a different vulnerability than CVE-2011-4458 and CVE-2011-5092.
OSV
CVE-2011-4458: Best Practical Solutions RT 3
osv·2012-06-04·CVSS 6.8
CVE-2011-4458 [MEDIUM] CVE-2011-4458: Best Practical Solutions RT 3
Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-5092 and CVE-2011-5093.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-5092 rt3: remote arbitrary code execution and privilege elevation flaw
bugzilla·2012-06-04·CVSS 6.8
CVE-2011-5092 [MEDIUM] CVE-2011-5092 rt3: remote arbitrary code execution and privilege elevation flaw
CVE-2011-5092 rt3: remote arbitrary code execution and privilege elevation flaw
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-5092 to
the following vulnerability:
Name: CVE-2011-5092
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5092
Assigned: 20120604
Reference: http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000203.html
Reference: http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000204.html
Reference: http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000202.html
Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6
allows remote attackers to execute arbitrary code and gain privileges
via unspecified vectors, a different vulnerability than CVE-2011-4458
and CVE-2011-5093.
Current Fedora has 3.8
Bugzilla
rt3: Multiple security flaws fixed in upstream v3.8.12 and v4.0.6 versions
bugzilla·2012-05-22·CVSS 4.3
CVE-2011-0009 [MEDIUM] rt3: Multiple security flaws fixed in upstream v3.8.12 and v4.0.6 versions
rt3: Multiple security flaws fixed in upstream v3.8.12 and v4.0.6 versions
Request Tracker (RT) upstream has announced upstream v3.8.12 and v4.0.6 versions:
http://blog.bestpractical.com/2012/05/security-vulnerabilities-in-rt.html
correcting the following security flaws:
The previously released tool to upgrade weak password hashes as part of CVE-2011-0009 was an incomplete fix and failed to upgrade passwords of disabled users. This release includes an updated version of the vulnerable-passwords tool, which should be run again to upgrade the remaining password hashes. CVE-2011-2082 is assigned to this vulnerability.
RT versions 3.0 and above contain a number of cross-site scripting (XSS) vulnerabilities which allow an attacker to run JavaScript with the user's credentials. CVE-2011-2083
http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000202.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2012-May/000203.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2012-May/000204.htmlhttp://secunia.com/advisories/49259http://www.securityfocus.com/bid/53660http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000202.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2012-May/000203.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2012-May/000204.htmlhttp://secunia.com/advisories/49259http://www.securityfocus.com/bid/53660
2012-06-04
Published