CVE-2009-3611
published 2009-10-26CVE-2009-3611: common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which…
PriorityP423high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.30%
22.2th percentile
common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| backintime_project | backintime | >= 0 < 0.9.26-3 | 0.9.26-3 |
| backintime_project | backintime | >= 0 < 0.9.26-3 | 0.9.26-3 |
| backintime_project | backintime | >= 0 < 0.9.26-3 | 0.9.26-3 |
| backintime_project | backintime | >= 0 < 0.9.26-3 | 0.9.26-3 |
| debian | backintime | < backintime 0.9.26-3 (bookworm) | backintime 0.9.26-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| le-web | backintime | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
backintime: makes all files world-readable in snapshot when removing it
vendor_redhat·2009-08-27·CVSS 7.1
CVE-2009-3611 [HIGH] backintime: makes all files world-readable in snapshot when removing it
backintime: makes all files world-readable in snapshot when removing it
common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.
Debian
CVE-2009-3611: backintime - common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain perm...
vendor_debian·2009·CVSS 7.1
CVE-2009-3611 [HIGH] CVE-2009-3611: backintime - common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain perm...
common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.
Scope: local
bookworm: resolved (fixed in 0.9.26-3)
bullseye: resolved (fixed in 0.9.26-3)
forky: resolved (fixed in 0.9.26-3)
sid: resolved (fixed in 0.9.26-3)
trixie: resolved (fixed in 0.9.26-3)
GHSA
GHSA-vvf9-jwf6-834q: common/snapshots
ghsa_unreviewed·2022-05-02
CVE-2009-3611 [LOW] CWE-732 GHSA-vvf9-jwf6-834q: common/snapshots
common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.
OSV
CVE-2009-3611: common/snapshots
osv·2009-10-26·CVSS 7.1
CVE-2009-3611 [HIGH] CVE-2009-3611: common/snapshots
common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543785http://bugs.gentoo.org/show_bug.cgi?id=289047http://ftp.debian.org/debian/pool/main/b/backintime/backintime_0.9.26-3.diff.gzhttp://marc.info/?l=oss-security&m=125553645511436&w=2http://marc.info/?l=oss-security&m=125554894700336&w=2https://bugs.launchpad.net/ubuntu/+source/backintime/+bug/434256https://bugzilla.redhat.com/show_bug.cgi?id=520210https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00821.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-September/msg00823.htmlhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543785http://bugs.gentoo.org/show_bug.cgi?id=289047http://ftp.debian.org/debian/pool/main/b/backintime/backintime_0.9.26-3.diff.gzhttp://marc.info/?l=oss-security&m=125553645511436&w=2http://marc.info/?l=oss-security&m=125554894700336&w=2https://bugs.launchpad.net/ubuntu/+source/backintime/+bug/434256https://bugzilla.redhat.com/show_bug.cgi?id=520210https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00821.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-September/msg00823.html
2009-10-26
Published