« Volver al listado

CVE-2009-5067

Estado: ModificadaMedia (4.3)—

Directory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a .. (dot dot) in the "include file" SSI directive. NOTE: this issue only might be a vulnerability in limited scenarios, such as if html2ps is invoked by a web application, or if a user-assisted attacker provides filenames whose contents could cause a denial of service, such as certain devices.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-5067",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-10-10T18:55:01.817",
  "references": [
    {
      "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=548633",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://packetstormsecurity.org/files/81614/html2ps-1.0-beta5-File-Disclosure.html",
      "tags": [
        "Exploit"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://user.it.uu.se/~jan/html2ps-1.0b7.tar.gz",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2012:161",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/10/05/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/10/05/5",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/36524",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=526513",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=548633",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://packetstormsecurity.org/files/81614/html2ps-1.0-beta5-File-Disclosure.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://user.it.uu.se/~jan/html2ps-1.0b7.tar.gz",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2012:161",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/10/05/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/10/05/5",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/36524",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=526513",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Directory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a .. (dot dot) in the \"include file\" SSI directive.  NOTE: this issue only might be a vulnerability in limited scenarios, such as if html2ps is invoked by a web application, or if a user-assisted attacker provides filenames whose contents could cause a denial of service, such as certain devices."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de salto de directorio en html2ps anteriores a v1.0b6 permite a atacantes remotos leer ficheros determinados al utilizar caracteres .. (punto punto) en la directiva \"include file\" de SSI. NOTA: este comportamiento sólo sería una vulnerabilidad en ciertos escenarios limitados, como en la invocación de html2ps por una aplicación web, o si un atacante asistidos por un usuario proporciona ficheros cuyo contenido pudiera causar una denegación de servicio, como ciertos dispositivos."
    }
  ],
  "lastModified": "2026-06-16T23:14:56.057",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:html2ps_project:html2ps:*:b5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4084CE5-07F7-4614-8513-9B8B7F08D383",
              "versionEndIncluding": "1.0"
            },
            {
              "criteria": "cpe:2.3:a:html2ps_project:html2ps:1.0:b1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3B5F6EE-0BB8-452F-B54C-33FB05A1F108"
            },
            {
              "criteria": "cpe:2.3:a:html2ps_project:html2ps:1.0:b2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44C0BC6E-5467-48AC-B770-634ACA1AE05A"
            },
            {
              "criteria": "cpe:2.3:a:html2ps_project:html2ps:1.0:b3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "447EF769-B549-47BA-8CAC-48CCB35F8A95"
            },
            {
              "criteria": "cpe:2.3:a:html2ps_project:html2ps:1.0:b4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CF43F95-7D88-4B1B-813D-BC6A3B3423C1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}