common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543785 | mailing list |
http://bugs.gentoo.org/show_bug.cgi?id=289047 | issue tracking patch |
http://ftp.debian.org/debian/pool/main/b/backintime/backintime_0.9.26-3.diff.gz | patch broken link |
http://marc.info/?l=oss-security&m=125554894700336&w=2 | mailing list |
https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00821.html | mailing list vendor advisory |
http://marc.info/?l=oss-security&m=125553645511436&w=2 | mailing list |
https://bugs.launchpad.net/ubuntu/+source/backintime/+bug/434256 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=520210 | issue tracking |
https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00823.html | mailing list vendor advisory |