Storebackup creates a temporary file predictably, which can be
exploited to overwrite arbitrary files on the system with a symlink
attack.
CVE-2005-3147
The backup root directory is created with world-readable permissions,
which may leak sensitive data.
CVE-2005-3148
The user and group rights of symlinks are set incorrectly when making
or restoring a backup, which may leak sensitive data.
The old stable distribution (woody) doesn't contain storebackup packages.
For the stable distribution (sarge) these problems have been fixed in
version 1.18.4-2sarge1.
For the unstable distribution (sid) these problems have been fixed in
version 1.19-2.
We recommend that you upgrade your storebackup package.
Upgrade Instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
...
Get the latest Linux and open source security news straight to your inbox.