Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-3369

Опубликовано: 18 авг. 2009
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=518412BackupPC: Permission bypass via ClientNameAlias by using rsync data backup method

EPSS

Процентиль: 89%
0.0443
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 16 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

nvd
больше 16 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

debian
больше 16 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in us ...

github
почти 4 года назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

EPSS

Процентиль: 89%
0.0443
Низкий

5.8 Medium

CVSS2