Back In Time Insecure File Permissions Vulnerability
BID:36525
Info
Back In Time Insecure File Permissions Vulnerability
| Bugtraq ID: | 36525 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 25 2009 12:00AM |
| Updated: | Apr 13 2015 09:55PM |
| Credit: | Rémi Vanicat |
| Vulnerable: |
Back In Time Back In Time 0.9.26 |
| Not Vulnerable: | |
Discussion
Back In Time Insecure File Permissions Vulnerability
Back In Time is prone to an insecure-file-permissions vulnerability.
An attacker can exploit this issue to modify files or obtain sensitive information that may aid in further attacks.
Back In Time 0.9.26 is vulnerable; other versions may also be affected.
Back In Time is prone to an insecure-file-permissions vulnerability.
An attacker can exploit this issue to modify files or obtain sensitive information that may aid in further attacks.
Back In Time 0.9.26 is vulnerable; other versions may also be affected.
Exploit / POC
Back In Time Insecure File Permissions Vulnerability
Attackers can use readily available tools and standard commands to exploit this issue.
Attackers can use readily available tools and standard commands to exploit this issue.
Solution / Fix
Back In Time Insecure File Permissions Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Back In Time Insecure File Permissions Vulnerability
References:
References:
- Bug 520210 - backintime: makes all files world-readable in snapshot when remov (Vincent Danen)
- Back In Time Homepage (Back In Time)
- backintime-common: backintime make world readable file in backup when it remove (Rémi Vanicat)