backuppc: privilege escalation
| Package(s): | backuppc | CVE #(s): | CVE-2009-3369 | ||||||||||||||||
| Created: | October 1, 2009 | Updated: | October 27, 2009 | ||||||||||||||||
| Description: | From the Mandriva alert:
CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore. | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
