VDB
DEBIAN-CVE-2009-3369
DEBIAN-CVE-2009-3369
PUBLISHED
CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | backuppc | 0, 0, 0 |
| Debian:13 | backuppc | 0, 0, 0 |
| Debian:14 | backuppc | 0, 0, 0 |
| Debian:12 | backuppc | 0, 0, 0 |
Timeline
- Sep 24, 2009 CVE Published
- Aug 4, 2026 CVE Updated