CVE-2020-7040
published 2020-01-21CVE-2020-7040: storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege…
PriorityP343high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.87%
85.2th percentile
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin manually deletes that file.)
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | storebackup | < storebackup 3.2.1-2 (bookworm) | storebackup 3.2.1-2 (bookworm) |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| storebackup | storebackup | <= 3.5 | — |
| storebackup | storebackup | >= 0 < 3.2.1-2 | 3.2.1-2 |
| storebackup | storebackup | >= 0 < 3.2.1-2 | 3.2.1-2 |
| storebackup | storebackup | >= 0 < 3.2.1-2 | 3.2.1-2 |
| storebackup | storebackup | >= 0 < 3.2.1-1+deb8u1build0.16.04.1 | 3.2.1-1+deb8u1build0.16.04.1 |
| storebackup | storebackup | >= 0 < 3.2.1-1+deb8u1build0.18.04.1 | 3.2.1-1+deb8u1build0.18.04.1 |
| storebackup | storebackup | >= 0 < 3.2.1-1+deb8u1build0.20.04.1 | 3.2.1-1+deb8u1build0.20.04.1 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.1HIGH
vendor_debian8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gc95-jc79-5q6h: storeBackup
ghsa_unreviewed·2022-05-24
CVE-2020-7040 [HIGH] CWE-59 GHSA-gc95-jc79-5q6h: storeBackup
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin manually deletes that file.)
OSV
storebackup vulnerability
osv·2020-09-16·CVSS 8.1
CVE-2020-7040 [HIGH] storebackup vulnerability
storebackup vulnerability
It was discovered that StoreBackup did not properly manage lock files.
A local attacker could use this issue to cause a denial of service or
escalate privileges and run arbitrary code. (CVE-2020-7040)
OSV
CVE-2020-7040: storeBackup
osv·2020-01-21·CVSS 8.1
CVE-2020-7040 [HIGH] CVE-2020-7040: storeBackup
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin manually deletes that file.)
Ubuntu
StoreBackup vulnerability
vendor_ubuntu·2020-09-16·CVSS 8.1
CVE-2020-7040 [HIGH] StoreBackup vulnerability
Title: StoreBackup vulnerability
Summary: StoreBackup could be made to stop executing or generate a race condition
if it received a lock file in the default location.
It was discovered that StoreBackup did not properly manage lock files.
A local attacker could use this issue to cause a denial of service or
escalate privileges and run arbitrary code. (CVE-2020-7040)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-7040: storebackup - storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pa...
vendor_debian·2020·CVSS 8.1
CVE-2020-7040 [HIGH] CVE-2020-7040: storebackup - storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pa...
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin manually deletes that file.)
Scope: local
bookworm: resolved (fixed in 3.2.1-2)
bullseye: resolved (fixed in 3.2.1-2)
sid: resolved (fixed in 3.2.1-2)
trixie: resolved (fixed in 3.2.1-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00054.htmlhttp://www.openwall.com/lists/oss-security/2020/01/20/3http://www.openwall.com/lists/oss-security/2020/01/21/2http://www.openwall.com/lists/oss-security/2020/01/22/2http://www.openwall.com/lists/oss-security/2020/01/22/3http://www.openwall.com/lists/oss-security/2020/01/23/1https://bugzilla.suse.com/show_bug.cgi?id=CVE-2020-7040https://lists.debian.org/debian-lts-announce/2020/02/msg00003.htmlhttps://seclists.org/oss-sec/2020/q1/20https://usn.ubuntu.com/4508-1/http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00054.htmlhttp://www.openwall.com/lists/oss-security/2020/01/20/3http://www.openwall.com/lists/oss-security/2020/01/21/2http://www.openwall.com/lists/oss-security/2020/01/22/2http://www.openwall.com/lists/oss-security/2020/01/22/3http://www.openwall.com/lists/oss-security/2020/01/23/1https://bugzilla.suse.com/show_bug.cgi?id=CVE-2020-7040https://lists.debian.org/debian-lts-announce/2020/02/msg00003.htmlhttps://seclists.org/oss-sec/2020/q1/20https://usn.ubuntu.com/4508-1/
2020-01-21
Published