First published: Wed Oct 05 2005(Updated: )
StoreBackup before 1.19 creates the backup root with world-readable permissions, which allows local users to obtain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Storebackup Storebackup | =1.1 | |
Storebackup Storebackup | =1.2 | |
Storebackup Storebackup | =1.3 | |
Storebackup Storebackup | =1.4 | |
Storebackup Storebackup | =1.5 | |
Storebackup Storebackup | =1.6 | |
Storebackup Storebackup | =1.7 | |
Storebackup Storebackup | =1.8 | |
Storebackup Storebackup | =1.8.1 | |
Storebackup Storebackup | =1.9 | |
Storebackup Storebackup | =1.9.1 | |
Storebackup Storebackup | =1.10 | |
Storebackup Storebackup | =1.10.1 | |
Storebackup Storebackup | =1.11 | |
Storebackup Storebackup | =1.12 | |
Storebackup Storebackup | =1.12.1 | |
Storebackup Storebackup | =1.12.2 | |
Storebackup Storebackup | =1.13 | |
Storebackup Storebackup | =1.14 | |
Storebackup Storebackup | =1.15 | |
Storebackup Storebackup | =1.16 | |
Storebackup Storebackup | =1.16.1 | |
Storebackup Storebackup | =1.16.2 | |
Storebackup Storebackup | =1.17 | |
Storebackup Storebackup | =1.18 | |
Storebackup Storebackup | =1.18.1 | |
Storebackup Storebackup | =1.18.2 | |
Storebackup Storebackup | =1.18.3 | |
Storebackup Storebackup | =1.18.4 | |
SUSE Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3147 has a medium severity rating due to its potential to expose sensitive information to local users.
To fix CVE-2005-3147, ensure that the backup directory is configured with the correct permissions to prevent world-readable access.
CVE-2005-3147 affects StoreBackup versions from 1.1 to 1.18.4.
CVE-2005-3147 is a vulnerability in StoreBackup that allows local users to access sensitive information due to insecure directory permissions.
Yes, updating to versions beyond 1.18.4 will resolve the vulnerability associated with CVE-2005-3147.