CVE-2009-3611
Summary
| CVE | CVE-2009-3611 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-10-26 16:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots. |
Risk And Classification
Primary CVSS: v3.1 7.1 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Problem Types: CWE-732 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.1 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
| 2.0 | [email protected] | Primary | 3.6 | AV:L/AC:L/Au:N/C:P/I:P/A:N |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 10 | All | All | All |
| Operating System | Fedoraproject | Fedora | 11 | All | All | All |
| Application | Le-web | Backintime | 0.9.26 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | ftp.debian.org | Broken Link, Patch |
| #543785 - backintime-common: backintime make world readable file in backup when it remove old backup - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | Mailing List |
| [SECURITY] Fedora 11 Update: backintime-0.9.26-3.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Mailing List |
| Bug 520210 – CVE-2009-3611 backintime: makes all files world-readable in snapshot when removing it | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking |
| [SECURITY] Fedora 10 Update: backintime-0.9.26-3.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Mailing List |
| Bug #434256 “Sync backintime 0.9.26-3 (universe) from Debian uns...” : Bugs : “backintime” package : Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | Third Party Advisory |
| '[oss-security] CVE Request - backintime' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List |
| 'Re: [oss-security] CVE Request - backintime' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List |
| 289047 – app-backup/backintime: Information disclosure when removing old backups (CVE-2009-3611) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | Issue Tracking, Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.