4.6
CVSSv2

CVE-2005-3148

Published: 05/10/2005 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

StoreBackup prior to 1.19 does not properly set the uid and guid for symbolic links (1) that are backed up by storeBackup.pl, or (2) recovered by storeBackupRecover.pl, which could cause files to be restored with incorrect ownership.

Vulnerable Product Search on Vulmon Subscribe to Product

storebackup storebackup 1.13

storebackup storebackup 1.14

storebackup storebackup 1.15

storebackup storebackup 1.16

storebackup storebackup 1.6

storebackup storebackup 1.7

storebackup storebackup 1.8

storebackup storebackup 1.8.1

storebackup storebackup 1.9

storebackup storebackup 1.10.1

storebackup storebackup 1.12

storebackup storebackup 1.12.2

storebackup storebackup 1.16.1

storebackup storebackup 1.17

storebackup storebackup 1.3

storebackup storebackup 1.5

storebackup storebackup 1.1

storebackup storebackup 1.10

storebackup storebackup 1.18.1

storebackup storebackup 1.18.2

storebackup storebackup 1.18.3

storebackup storebackup 1.18.4

storebackup storebackup 1.11

storebackup storebackup 1.12.1

storebackup storebackup 1.16.2

storebackup storebackup 1.18

storebackup storebackup 1.2

storebackup storebackup 1.4

storebackup storebackup 1.9.1

suse suse linux

Vendor Advisories

Several vulnerabilities have been discovered in the backup utility storebackup The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-3146 Storebackup creates a temporary file predictably, which can be exploited to overwrite arbitrary files on the system with a symlink attack CVE-2005-3147 Th ...