First published: Wed Oct 05 2005(Updated: )
StoreBackup before 1.19 allows local users to perform unauthorized operations on arbitrary files via a symlink attack on temporary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Storebackup Storebackup | =1.1 | |
Storebackup Storebackup | =1.2 | |
Storebackup Storebackup | =1.3 | |
Storebackup Storebackup | =1.4 | |
Storebackup Storebackup | =1.5 | |
Storebackup Storebackup | =1.6 | |
Storebackup Storebackup | =1.7 | |
Storebackup Storebackup | =1.8 | |
Storebackup Storebackup | =1.8.1 | |
Storebackup Storebackup | =1.9 | |
Storebackup Storebackup | =1.9.1 | |
Storebackup Storebackup | =1.10 | |
Storebackup Storebackup | =1.10.1 | |
Storebackup Storebackup | =1.11 | |
Storebackup Storebackup | =1.12 | |
Storebackup Storebackup | =1.12.1 | |
Storebackup Storebackup | =1.12.2 | |
Storebackup Storebackup | =1.13 | |
Storebackup Storebackup | =1.14 | |
Storebackup Storebackup | =1.15 | |
Storebackup Storebackup | =1.16 | |
Storebackup Storebackup | =1.16.1 | |
Storebackup Storebackup | =1.16.2 | |
Storebackup Storebackup | =1.17 | |
Storebackup Storebackup | =1.18 | |
Storebackup Storebackup | =1.18.1 | |
Storebackup Storebackup | =1.18.2 | |
Storebackup Storebackup | =1.18.3 | |
Storebackup Storebackup | =1.18.4 | |
SUSE Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3146 is classified as a moderate severity vulnerability.
To fix CVE-2005-3146, upgrade to StoreBackup version 1.19 or later to mitigate the symlink attack risk.
CVE-2005-3146 affects local users of StoreBackup versions prior to 1.19.
CVE-2005-3146 describes a symlink attack that allows unauthorized operations on arbitrary files.
There are no official workarounds for CVE-2005-3146; upgrading to a patched version is recommended.