FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-2944

This CVE name corresponds to:

Entered Topic
2009-09-13 ikiwiki -- insufficient blacklisting in teximg plugin

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-2944
Phase Assigned(20090823)

Description

Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands.

References

Source Reference
CONFIRM http://ikiwiki.info/security/#index35h2
DEBIAN DSA-1875
BID 36181
OSVDB 57575
SECUNIA 36516
SECUNIA 36539
VUPEN ADV-2009-2475
XF ikiwiki-teximg-info-disclosure(52922)