CVE-2009-4405: SQL Injection

Published Nov 29, 2009
·
Updated

Description of problem: The latest upstream version is 0.11.6 (released yesterday). The current Fedora 12 (and rawhide version) is 0.11.4.

Version-Release number of selected component (if applicable): trac-0.11.4-2.fc12.src.rpm

Expected results: To have trac 0.11.6 available for F-12 and rawhide.

Additional info:

Release notes from versions 0.11.5 and 0.11.6: ---------- http://trac.edgewall.org/browser/tags/trac-0.11.5/RELEASE ---------- Changes in 0.11.5

Implemented pre-upgrade backup support for PostgreSQL and MySQL (#2304) Fixed PostgreSQL upgrade issue (#8378) More robust diff parsing (#2672) Avoid intermittent hangs by not calling aprterminate explicitly (#7785) Fixed display of merge properties for scoped repositories #7715. ---------- http://trac.edgewall.org/browser/tags/trac-0.11.6/RELEASE ---------- Changes in 0.11.6

Fixed the policy checks in report results when using alternate formats. Added a check for the "raw" role that is missing in docutils < 0.6. Re-enabled connection pooling with SQLite (#3446). Added caching of configuration options (#8510). Fixed the "database is locked" issue with SQLite (#3446, #8468). Deprecated SQLite 2.x support (#8625). Fixed hanlding of times in timezones with DST (#8240). Avoid corruption of trac.ini during write (#8623). Improved support for revision ranges in the revision log view (#8349) ----------

Other sources

Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) "policy checks in report results when using alternate formats" or (2) a "check for the 'raw' role that is missing in docutils < 0.6."

MITRE

Affected Software

47 affected componentsFixes available
redhat/0.11.6<1.
1.
pip/trac<0.11.6
0.11.6
edgewall trac<=0.11.5
edgewall trac=0.5
edgewall trac=0.5.1
edgewall trac=0.5.2
edgewall trac=0.6
edgewall trac=0.6.1
edgewall trac=0.7
edgewall trac=0.7.1
edgewall trac=0.8
edgewall trac=0.8.1
edgewall trac=0.8.2
edgewall trac=0.8.3
edgewall trac=0.8.4
edgewall trac=0.9
edgewall trac=0.9.1
edgewall trac=0.9.2
edgewall trac=0.9.3
edgewall trac=0.9.4
edgewall trac=0.9.5
edgewall trac=0.9.6
edgewall trac=0.10
edgewall trac=0.10-beta1
edgewall trac=0.10-rc1
edgewall trac=0.10.1
edgewall trac=0.10.2
edgewall trac=0.10.3
edgewall trac=0.10.3-rc1
edgewall trac=0.10.3.1
edgewall trac=0.10.4
edgewall trac=0.10.5
edgewall trac=0.11
edgewall trac=0.11-b1
edgewall trac=0.11-b2
edgewall trac=0.11-rc1
edgewall trac=0.11-rc2
edgewall trac=0.11.1
edgewall trac=0.11.2
edgewall trac=0.11.2.1
edgewall trac=0.11.3
edgewall trac=0.11.4
edgewall trac=0.11.4-rc1
edgewall trac=0.11.4-rc2
edgewall trac=0.11.5-rc1
edgewall trac=0.11.5-rc2
edgewall trac=0.50.9

Event History

Dec 23, 2009
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
May 2, 2022
Advisory Published
via GitHub·03:54 AM

Frequently Asked Questions

1

What is the severity of CVE-2009-4405?

CVE-2009-4405 is classified as a moderate severity vulnerability.

2

How do I fix CVE-2009-4405?

To fix CVE-2009-4405, upgrade to Edgewall Trac version 0.11.6 or later.

3

What versions are affected by CVE-2009-4405?

CVE-2009-4405 affects Edgewall Trac versions up to 0.11.5 inclusive.

4

Is there a workaround for CVE-2009-4405?

A workaround for CVE-2009-4405 is not available; upgrading is recommended.

5

Can I check my Trac version to see if I'm vulnerable to CVE-2009-4405?

Yes, you can check your Trac version by using the command line or by accessing the web interface.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203