CVE-2005-1856: Low severity backup manager vulnerability
Published Aug 29, 2005
·Updated
The CD-burning feature in backup-manager 0.5.8 and earlier uses a fixed filename in a world-writable directory for logging, which allows local users to overwrite files via a symlink attack.
Affected Software
4 affected components
Sukria Backup Manager=0.5.7
Sukria Backup Manager=0.5.6
Sukria Backup Manager=0.5.6
Sukria Backup Manager=0.5.7
Remediation
Patch Available
Event History
Aug 29, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1856?
CVE-2005-1856 is considered a moderate severity vulnerability due to its potential for local file overwrite via a symlink attack.
2
How do I mitigate CVE-2005-1856?
To mitigate CVE-2005-1856, upgrade to backup-manager version 0.5.8 or later where this vulnerability is fixed.
3
Which versions of backup-manager are affected by CVE-2005-1856?
Backup-manager versions 0.5.6 and 0.5.7 are vulnerable to CVE-2005-1856.
4
What is the nature of the vulnerability in CVE-2005-1856?
CVE-2005-1856 allows local users to perform a symlink attack due to the use of a fixed filename in a world-writable directory for logging.
5
Can CVE-2005-1856 be exploited remotely?
No, CVE-2005-1856 is a local vulnerability that requires local access to exploit.