A vulnerability has been discovered in btrbk which can lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202402-32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: btrbk: Remote Code Execution Date: February 26, 2024 Bugs: #806962 ID: 202402-32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in btrbk which can lead to remote code execution. Background ========== btrbk is a backup tool for btrfs subvolumes, taking advantage of btrfs specific capabilities to create atomic snapshots and transfer them incrementally to your backup locations. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ app-backup/btrbk < 0.31.2 > = 0.31.2 Description =========== A vulnerability has been discovered in btrbk. Please review the CVE identifier referenced below for details. Impact ====== Specialy crafted commands may be executed without being propely checked. Applies to remote hosts filtering ssh commands using ssh_filter_btrbk.sh in authorized_keys. Workaround ========== There is no known workaround at this time. Resolution ========== All btrbk users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-backup/btrbk-0.31.2" References ========== [ 1 ] CVE-2021-38173 https://nvd.nist.gov/vuln/detail/CVE-2021-38173 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202402-32 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and securityof our users' machines is of utmost importance to us. Any security concerns should be addressed to
Remove executable permissions from scripts in /usr/shar. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-a66734e7a2 2022-01-19 02:10:14.239473 --------------------------------------------------------------------------------Name : btrbk Product : Fedora 35 Version : 0.31.3 Release : 1.fc35 URL : https://digint.ch/btrbk/ Summary : Tool for creating snapshots and remote backups of btrfs sub-volumes Description : Backup tool for btrfs sub-volumes, using a configuration file, allows creation of backups from multiple sources to multiple destinations, with ssh and flexible retention policy support (hourly, daily, weekly, monthly) --------------------------------------------------------------------------------Update Information: Remove executable permissions from scripts in /usr/shar --------------------------------------------------------------------------------ChangeLog: * Mon Jan 10 2022 Juan Orti Alcaine - 0.31.3-1 - Version 0.31.3 (#1765928) - Remove executable permissions from scripts in /usr/share (#1994989) --------------------------------------------------------------------------------References: [ 1 ] Bug #1994989 - CVE-2021-38173 btrbk: remote execution in ssh_filter_btrbk.sh [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1994989 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-a66734e7a2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Remove executable permissions from scripts in /usr/share. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-dc62389784 2022-01-19 01:53:29.295579 --------------------------------------------------------------------------------Name : btrbk Product : Fedora 34 Version : 0.31.3 Release : 1.fc34 URL : https://digint.ch/btrbk/ Summary : Tool for creating snapshots and remote backups of btrfs sub-volumes Description : Backup tool for btrfs sub-volumes, using a configuration file, allows creation of backups from multiple sources to multiple destinations, with ssh and flexible retention policy support (hourly, daily, weekly, monthly) --------------------------------------------------------------------------------Update Information: Remove executable permissions from scripts in /usr/share --------------------------------------------------------------------------------ChangeLog: * Mon Jan 10 2022 Juan Orti Alcaine - 0.31.3-1 - Version 0.31.3 (#1765928) - Remove executable permissions from scripts in /usr/share (#1994989) * Wed Jul 21 2021 Fedora Release Engineering - 0.28.3-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1994989 - CVE-2021-38173 btrbk: remote execution in ssh_filter_btrbk.sh [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1994989 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-dc62389784' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An issue has been found in btrbk, a backup tool for btrfs subvolumes. Due to mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys an arbitrary code execution would . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2755-1
Get the latest Linux and open source security news straight to your inbox.