7.1
CVE-2009-3611
- EPSS 0.3%
- Veröffentlicht 26.10.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:12:00
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.217 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
| nvd@nist.gov | 3.6 | 3.9 | 4.9 |
AV:L/AC:L/Au:N/C:P/I:P/A:N
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543785
http://bugs.gentoo.org/show_bug.cgi?id=289047
http://ftp.debian.org/debian/pool/main/b/backintime/backintime_0.9.26-3.diff.gz
http://marc.info/?l=oss-security&m=125553645511436&w=2
http://marc.info/?l=oss-security&m=125554894700336&w=2
https://bugs.launchpad.net/ubuntu/+source/backintime/+bug/434256
https://bugzilla.redhat.com/show_bug.cgi?id=520210
https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00821.html
https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00823.html