Borg (aka BorgBackup) before 1.0.9 has a flaw in the way duplicate archive names were processed during manifest recovery, potentially allowing an attacker to overwrite an archive.
                
            References
                    | Link | Resource | 
|---|---|
| http://borgbackup.readthedocs.io/en/stable/changes.html#pre-1-0-9-manifest-spoofing-vulnerability | Mitigation Vendor Advisory | 
| http://www.securityfocus.com/bid/95203 | |
| http://borgbackup.readthedocs.io/en/stable/changes.html#pre-1-0-9-manifest-spoofing-vulnerability | Mitigation Vendor Advisory | 
| http://www.securityfocus.com/bid/95203 | 
Configurations
                    History
                    No history.
Information
                Published : 2017-01-02 21:59
Updated : 2025-04-12 10:46
NVD link : CVE-2016-10100
Mitre link : CVE-2016-10100
CVE.ORG link : CVE-2016-10100
JSON object : View
Products Affected
                borg
- borg
 
CWE
                
                    
                        
                        CWE-20
                        
            Improper Input Validation
