CVE-2011-5092
published 2012-06-04CVE-2011-5092: Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges via unspecified…
PriorityP345high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.85%
84.9th percentile
Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges via unspecified vectors, a different vulnerability than CVE-2011-4458 and CVE-2011-5093.
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2011-4458: request-tracker4 - Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before...
vendor_debian·2011·CVSS 6.8
CVE-2011-4458 [MEDIUM] CVE-2011-4458: request-tracker4 - Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before...
Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-5092 and CVE-2011-5093.
Scope: local
bookworm: resolved (fixed in 4.0.5-3)
bullseye: resolved (fixed in 4.0.5-3)
sid: resolved (fixed in 4.0.5-3)
GHSA
GHSA-jv9v-724f-v2g6: Best Practical Solutions RT 3
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2011-5092 [MEDIUM] GHSA-jv9v-724f-v2g6: Best Practical Solutions RT 3
Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges via unspecified vectors, a different vulnerability than CVE-2011-4458 and CVE-2011-5093.
GHSA
GHSA-397q-whxp-h2p3: Best Practical Solutions RT 3
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2011-4458 [HIGH] CWE-94 GHSA-397q-whxp-h2p3: Best Practical Solutions RT 3
Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-5092 and CVE-2011-5093.
GHSA
GHSA-3hp8-xj8q-7jfq: Best Practical Solutions RT 4
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2011-5093 [MEDIUM] GHSA-3hp8-xj8q-7jfq: Best Practical Solutions RT 4
Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated users to bypass intended access restrictions and execute arbitrary code by leveraging access to a privileged account, a different vulnerability than CVE-2011-4458 and CVE-2011-5092.
OSV
CVE-2011-4458: Best Practical Solutions RT 3
osv·2012-06-04·CVSS 6.8
CVE-2011-4458 [MEDIUM] CVE-2011-4458: Best Practical Solutions RT 3
Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-5092 and CVE-2011-5093.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-5092 rt3: remote arbitrary code execution and privilege elevation flaw
bugzilla·2012-06-04·CVSS 6.8
CVE-2011-5092 [MEDIUM] CVE-2011-5092 rt3: remote arbitrary code execution and privilege elevation flaw
CVE-2011-5092 rt3: remote arbitrary code execution and privilege elevation flaw
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-5092 to
the following vulnerability:
Name: CVE-2011-5092
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5092
Assigned: 20120604
Reference: http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000203.html
Reference: http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000204.html
Reference: http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000202.html
Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6
allows remote attackers to execute arbitrary code and gain privileges
via unspecified vectors, a different vulnerability than CVE-2011-4458
and CVE-2011-5093.
Current Fedora has 3.8
Bugzilla
CVE-2011-5092 rt3: remote arbitrary code execution and privilege elevation flaw [epel-6]
bugzilla·2012-06-04·CVSS 7.5
CVE-2011-5092 [HIGH] CVE-2011-5092 rt3: remote arbitrary code execution and privilege elevation flaw [epel-6]
CVE-2011-5092 rt3: remote arbitrary code execution and privilege elevation flaw [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?t
http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000202.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2012-May/000203.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2012-May/000204.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2012-May/000202.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2012-May/000203.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2012-May/000204.html
2012-06-04
Published