| Vulnerability Name: | CVE-2005-1856 (CCN-21350) | ||||||||
| Assigned: | 2005-07-11 | ||||||||
| Published: | 2005-07-11 | ||||||||
| Updated: | 2008-09-05 | ||||||||
| Summary: | The CD-burning feature in backup-manager 0.5.8 and earlier uses a fixed filename in a world-writable directory for logging, which allows local users to overwrite files via a symlink attack. | ||||||||
| CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-2005-1856 Source: MITRE Type: CNA CVE-2005-2211 Source: MITRE Type: CNA CVE-2005-2212 Source: CCN Type: SA15989 Backup Manager Unspecified Insecure Temporary File Creation Source: DEBIAN Type: Patch, Vendor Advisory DSA-787 Source: DEBIAN Type: DSA-787 backup-manager -- insecure permissions and tempfile Source: CCN Type: OSVDB ID: 27434 backup-manager CD-burning Feature Symlink Arbitrary File Overwrite Source: CCN Type: BID-14210 Backup Manager Insecure Temporary File Creation Vulnerability Source: CCN Type: Backup Manager Web site sukria.net - Backup Manager - A small Linux tool for making backups Source: XF Type: UNKNOWN backup-cdr-temporary-file(21350) | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| Oval Definitions | |||||||||
| |||||||||
| BACK | |||||||||