LWN.net Logo

backintime: incorrect file permissions when removing backup

Package(s):backintime CVE #(s):
Created:September 28, 2009 Updated:September 30, 2009
Description:

From the Red Hat bugzilla entry:

A Debian bug reportindicates that backintime chmods files to mode 0777 prior to removing them via removing a snapshot. What makes this worse is that if those files exist in subsequent snapshots, the permissions on those files is also mode 0777 which allows anyone to manipulate/delete the files in the backup.

Alerts:
Fedora FEDORA-2009-9282 2009-09-04
Fedora FEDORA-2009-9298 2009-09-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds