CVE-2005-3148
Summary
| CVE | CVE-2005-3148 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-10-05 21:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | StoreBackup before 1.19 does not properly set the uid and guid for symbolic links (1) that are backed up by storeBackup.pl, or (2) recovered by storeBackupRecover.pl, which could cause files to be restored with incorrect ownership. |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Storebackup | Storebackup | 1.1 | All | All | All |
| Application | Storebackup | Storebackup | 1.10 | All | All | All |
| Application | Storebackup | Storebackup | 1.10.1 | All | All | All |
| Application | Storebackup | Storebackup | 1.11 | All | All | All |
| Application | Storebackup | Storebackup | 1.12 | All | All | All |
| Application | Storebackup | Storebackup | 1.12.1 | All | All | All |
| Application | Storebackup | Storebackup | 1.12.2 | All | All | All |
| Application | Storebackup | Storebackup | 1.13 | All | All | All |
| Application | Storebackup | Storebackup | 1.14 | All | All | All |
| Application | Storebackup | Storebackup | 1.15 | All | All | All |
| Application | Storebackup | Storebackup | 1.16 | All | All | All |
| Application | Storebackup | Storebackup | 1.16.1 | All | All | All |
| Application | Storebackup | Storebackup | 1.16.2 | All | All | All |
| Application | Storebackup | Storebackup | 1.17 | All | All | All |
| Application | Storebackup | Storebackup | 1.18 | All | All | All |
| Application | Storebackup | Storebackup | 1.18.1 | All | All | All |
| Application | Storebackup | Storebackup | 1.18.2 | All | All | All |
| Application | Storebackup | Storebackup | 1.18.3 | All | All | All |
| Application | Storebackup | Storebackup | 1.18.4 | All | All | All |
| Application | Storebackup | Storebackup | 1.2 | All | All | All |
| Application | Storebackup | Storebackup | 1.3 | All | All | All |
| Application | Storebackup | Storebackup | 1.4 | All | All | All |
| Application | Storebackup | Storebackup | 1.5 | All | All | All |
| Application | Storebackup | Storebackup | 1.6 | All | All | All |
| Application | Storebackup | Storebackup | 1.7 | All | All | All |
| Application | Storebackup | Storebackup | 1.8 | All | All | All |
| Application | Storebackup | Storebackup | 1.8.1 | All | All | All |
| Application | Storebackup | Storebackup | 1.9 | All | All | All |
| Application | Storebackup | Storebackup | 1.9.1 | All | All | All |
| Operating System | Suse | Suse Linux | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| #332434 - storebackup: Several security problems (already fixed in sid/testing) - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| Debian -- Security Information -- DSA-1022-1 storebackup | af854a3a-2127-422b-91ae-364da2661108 | www.us.debian.org | |
| www.securityfocus.com/advisories/9384 | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Vendor Advisory |
| Secunia - Advisories - Debian update for storebackup | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SourceForge.net: Files | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Patch, Vendor Advisory |
| Secunia - Advisories - storeBackup Insecure Temporary File Creation and Insecure Backup Root Permissions | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.