CVE-2009-3611
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.
common/snapshots.py en Back In Time (también conocido como backintime) v0.9.26 cambia ciertos permisos al valor 0777 antes de eliminar los ficheros en una copia de seguridad antigua de un punto de restauración, lo que permite a usuarios locales obtener información sensible mediante la lectura de esos ficheros, o interferir con la integridad de la copia de seguridad modificando ficheros que están compartidos a través de puntos de restauración.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-10-09 CVE Reserved
- 2009-10-26 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543785 | Mailing List | |
http://marc.info/?l=oss-security&m=125553645511436&w=2 | Mailing List | |
http://marc.info/?l=oss-security&m=125554894700336&w=2 | Mailing List | |
https://bugs.launchpad.net/ubuntu/+source/backintime/+bug/434256 | Third Party Advisory | |
https://bugzilla.redhat.com/show_bug.cgi?id=520210 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://bugs.gentoo.org/show_bug.cgi?id=289047 | 2024-01-25 | |
http://ftp.debian.org/debian/pool/main/b/backintime/backintime_0.9.26-3.diff.gz | 2024-01-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Le-web Search vendor "Le-web" | Backintime Search vendor "Le-web" for product "Backintime" | 0.9.26 Search vendor "Le-web" for product "Backintime" and version "0.9.26" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 10 Search vendor "Fedoraproject" for product "Fedora" and version "10" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 11 Search vendor "Fedoraproject" for product "Fedora" and version "11" | - |
Affected
|