2024-12-08 03:06:42 +00:00

248 lines
7.1 KiB
JSON

{
"id": "CVE-2009-3611",
"sourceIdentifier": "secalert@redhat.com",
"published": "2009-10-26T16:30:00.890",
"lastModified": "2024-11-21T01:07:48.000",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots."
},
{
"lang": "es",
"value": "common/snapshots.py en Back In Time (tambi\u00e9n conocido como backintime) v0.9.26 cambia ciertos permisos al valor 0777 antes de eliminar los ficheros en una copia de seguridad antigua de un punto de restauraci\u00f3n, lo que permite a usuarios locales obtener informaci\u00f3n sensible mediante la lectura de esos ficheros, o interferir con la integridad de la copia de seguridad modificando ficheros que est\u00e1n compartidos a trav\u00e9s de puntos de restauraci\u00f3n.\r\n"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 1.8,
"impactScore": 5.2
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:N",
"baseScore": 3.6,
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "LOW",
"exploitabilityScore": 3.9,
"impactScore": 4.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-732"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:le-web:backintime:0.9.26:*:*:*:*:*:*:*",
"matchCriteriaId": "E6A8AFD9-1CE5-4985-911E-648A7206B365"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:*",
"matchCriteriaId": "7000D33B-F3C7-43E8-8FC7-9B97AADC3E12"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*",
"matchCriteriaId": "B3BB5EDB-520B-4DEF-B06E-65CA13152824"
}
]
}
]
}
],
"references": [
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543785",
"source": "secalert@redhat.com",
"tags": [
"Mailing List"
]
},
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=289047",
"source": "secalert@redhat.com",
"tags": [
"Issue Tracking",
"Patch"
]
},
{
"url": "http://ftp.debian.org/debian/pool/main/b/backintime/backintime_0.9.26-3.diff.gz",
"source": "secalert@redhat.com",
"tags": [
"Broken Link",
"Patch"
]
},
{
"url": "http://marc.info/?l=oss-security&m=125553645511436&w=2",
"source": "secalert@redhat.com",
"tags": [
"Mailing List"
]
},
{
"url": "http://marc.info/?l=oss-security&m=125554894700336&w=2",
"source": "secalert@redhat.com",
"tags": [
"Mailing List"
]
},
{
"url": "https://bugs.launchpad.net/ubuntu/+source/backintime/+bug/434256",
"source": "secalert@redhat.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=520210",
"source": "secalert@redhat.com",
"tags": [
"Issue Tracking"
]
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00821.html",
"source": "secalert@redhat.com",
"tags": [
"Mailing List"
]
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00823.html",
"source": "secalert@redhat.com",
"tags": [
"Mailing List"
]
},
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543785",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Mailing List"
]
},
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=289047",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Issue Tracking",
"Patch"
]
},
{
"url": "http://ftp.debian.org/debian/pool/main/b/backintime/backintime_0.9.26-3.diff.gz",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Broken Link",
"Patch"
]
},
{
"url": "http://marc.info/?l=oss-security&m=125553645511436&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Mailing List"
]
},
{
"url": "http://marc.info/?l=oss-security&m=125554894700336&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Mailing List"
]
},
{
"url": "https://bugs.launchpad.net/ubuntu/+source/backintime/+bug/434256",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=520210",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Issue Tracking"
]
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00821.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Mailing List"
]
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00823.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Mailing List"
]
}
]
}