storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin manually deletes that file.)
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2020-01-21 21:15
Updated : 2024-11-21 05:36
NVD link : CVE-2020-7040
Mitre link : CVE-2020-7040
CVE.ORG link : CVE-2020-7040
JSON object : View
Products Affected
storebackup
- storebackup
debian
- debian_linux
opensuse
- leap
- backports_sle
canonical
- ubuntu_linux
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')