VDB
CVE-2009-3611
CVE-2009-3611
PUBLISHED
CVSS 7.099999904632568 HIGH
common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.
EPSS 0.06% · 18.7th percentile
Risk Scores
CVSS 3.1
7.099999904632568
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.06%
18.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| le-web | backintime | 0.9.26 |
| fedoraproject | fedora | 10, 11 |
| n/a | n/a | n/a |
Timeline
- Oct 26, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543785 url
- http://bugs.gentoo.org/show_bug.cgi?id=289047 url
- http://ftp.debian.org/debian/pool/main/b/backintime/backintime_0.9.26-3.diff.gz url
- [oss-security] 20091014 Re: CVE Request - backintime mailing-list
- FEDORA-2009-9282 vendor-advisory
- [oss-security] 20091014 CVE Request - backintime mailing-list
- https://bugs.launchpad.net/ubuntu/+source/backintime/+bug/434256 url
- https://bugzilla.redhat.com/show_bug.cgi?id=520210 url
- FEDORA-2009-9298 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-3611 advisory