First published: Mon Aug 29 2005(Updated: )
The CD-burning feature in backup-manager 0.5.8 and earlier uses a fixed filename in a world-writable directory for logging, which allows local users to overwrite files via a symlink attack.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
sukria Backup Manager | =0.5.6 | |
sukria Backup Manager | =0.5.7 | |
sukria Backup Manager | =0.5.7 | |
sukria Backup Manager | =0.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1856 is considered a moderate severity vulnerability due to its potential for local file overwrite via a symlink attack.
To mitigate CVE-2005-1856, upgrade to backup-manager version 0.5.8 or later where this vulnerability is fixed.
Backup-manager versions 0.5.6 and 0.5.7 are vulnerable to CVE-2005-1856.
CVE-2005-1856 allows local users to perform a symlink attack due to the use of a fixed filename in a world-writable directory for logging.
No, CVE-2005-1856 is a local vulnerability that requires local access to exploit.