CVE-2009-3611

common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
VendorProductVersion
le-webbackintime
0.9.26
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
backintime
bullseye
1.2.1-3
fixed
bookworm
1.3.3-4
fixed
sid
1.5.2-1
fixed
trixie
1.5.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
backintime
jaunty
dne
intrepid
dne
hardy
dne
dapper
dne