CVE-2009-3369

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
backuppcbackuppc
3.1.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
backuppc
bookworm
4.4.0-8
fixed
bullseye
4.4.0-3
fixed
etch
not-affected
sid
4.4.0-10
fixed
trixie
4.4.0-10
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
backuppc
dapper
not-affected
hardy
Fixed 3.0.0-4ubuntu1.1
released
intrepid
Fixed 3.1.0-3ubuntu2.1
released
jaunty
Fixed 3.1.0-4ubuntu1.1
released
Common Weakness Enumeration