StoreBackup before 1.19 creates the backup root with world-readable permissions, which allows local users to obtain sensitive information.
Link | Tags |
---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=332434 | |
http://www.us.debian.org/security/2006/dsa-1022 | vendor advisory |
http://sourceforge.net/project/shownotes.php?release_id=352676 | patch |
http://secunia.com/advisories/19489 | third party advisory |
http://secunia.com/advisories/17025 | third party advisory |
http://www.securityfocus.com/advisories/9384 | vendor advisory |