CVE-2005-3111: Low severity Debian Backupninja vulnerability
Published Sep 30, 2005
·Updated
The handler code for backupninja 0.8 and earlier creates temporary files with predictable filenames, which allows local users to modify arbitrary files via a symlink attack.
Affected Software
1 affected component
Debian Backupninja<=0.8
Remediation
Patch Available
Event History
Sep 30, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3111?
CVE-2005-3111 is considered to be of medium severity due to its potential for local users to exploit the vulnerability via a symlink attack.
2
How does CVE-2005-3111 allow for exploitation?
CVE-2005-3111 allows exploitation by creating temporary files with predictable filenames, enabling local users to modify arbitrary files.
3
Which versions of Backupninja are affected by CVE-2005-3111?
CVE-2005-3111 affects Backupninja versions 0.8 and earlier.
4
How do I fix CVE-2005-3111?
To fix CVE-2005-3111, upgrade Backupninja to a version later than 0.8 that includes the security fix.
5
What type of attack does CVE-2005-3111 facilitate?
CVE-2005-3111 facilitates a symlink attack, allowing local users to manipulate files that they should not have access to.