Access Restriction Bypass Affecting backuppc package, versions <3.1.0-8


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.37% (73rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN8-BACKUPPC-288408
  • published24 Sept 2009
  • disclosed24 Sept 2009

Introduced: 24 Sep 2009

CVE-2009-3369  (opens in a new tab)
CWE-264  (opens in a new tab)

How to fix?

Upgrade Debian:8 backuppc to version 3.1.0-8 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream backuppc package and not the backuppc package as distributed by Debian. See How to fix? for Debian:8 relevant fixed versions and status.

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

CVSS Scores

version 3.1