VDB

DEBIAN-CVE-2009-3369

DEBIAN-CVE-2009-3369 PUBLISHED

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

Affected Products

VendorProductVersions
Debian:11backuppc0, 0, 0
Debian:13backuppc0, 0, 0
Debian:14backuppc0, 0, 0
Debian:12backuppc0, 0, 0

Timeline

  • Sep 24, 2009 CVE Published
  • Aug 4, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›