Vulnerabilities > CVE-2005-1855
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 | |
OS | 13 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-787.NASL |
description | Two bugs have been found in backup-manager, a command-line driven backup utility. The Common Vulnerabilities and Exposures project identifies the following problems : - CAN-2005-1855 Jeroen Vermeulen discovered that backup files are created with default permissions making them world readable, even though they may contain sensitive information. - CAN-2005-1856 Sven Joachim discovered that the optional CD-burning feature of backup-manager uses a hard-coded filename in a world-writable directory for logging. This can be subject to a symlink attack. The old stable distribution (woody) does not provide the backup-manager package. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19530 |
published | 2005-08-30 |
reporter | This script is Copyright (C) 2005-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/19530 |
title | Debian DSA-787-1 : backup-manager - insecure permissions and tempfile |
code |
|
References
- http://secunia.com/advisories/15615
- http://secunia.com/advisories/15615
- http://securitytracker.com/id?1014124
- http://securitytracker.com/id?1014124
- http://www.debian.org/security/2005/dsa-787
- http://www.debian.org/security/2005/dsa-787
- http://www.securityfocus.com/bid/13892
- http://www.securityfocus.com/bid/13892
- http://www.sukria.net/packages/backup-manager/
- http://www.sukria.net/packages/backup-manager/
- http://www.usenetlinux.com/archive/index.php/t-411815.html
- http://www.usenetlinux.com/archive/index.php/t-411815.html