Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-3369

Опубликовано: 24 сент. 2009
Источник: ubuntu
Приоритет: medium
CVSS2: 8.5

Описание

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

РелизСтатусПримечание
dapper

not-affected

code not present
devel

released

3.1.0-6ubuntu4
hardy

released

3.0.0-4ubuntu1.1
intrepid

released

3.1.0-3ubuntu2.1
jaunty

released

3.1.0-4ubuntu1.1
upstream

released

3.1.0-7

Показывать по

8.5 High

CVSS2

Связанные уязвимости

redhat
больше 16 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

nvd
около 16 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

debian
около 16 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in us ...

github
больше 3 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

8.5 High

CVSS2