Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-3369

Опубликовано: 18 авг. 2009
Источник: redhat
CVSS2: 5.8

Описание

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=518412BackupPC: Permission bypass via ClientNameAlias by using rsync data backup method

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

nvd
около 16 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

debian
около 16 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in us ...

github
больше 3 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

5.8 Medium

CVSS2