LWN.net Logo

backuppc: privilege escalation

Package(s):backuppc CVE #(s):CVE-2009-3369
Created:October 1, 2009 Updated:October 27, 2009
Description: From the Mandriva alert:

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

Alerts:
Mandriva MDVSA-2009:253 2009-10-01
Ubuntu USN-843-1 2009-10-06
Fedora FEDORA-2009-9982 2009-09-29
Fedora FEDORA-2009-9973 2009-09-29

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds