Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 308013 (CVE-2009-3369) - <app-backup/backuppc-3.2.1: information leak and XSS (CVE-2009-3369, CVE-2011-3361)
Summary: <app-backup/backuppc-3.2.1: information leak and XSS (CVE-2009-3369, CVE-2011...
Status: RESOLVED FIXED
Alias: CVE-2009-3369
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: C4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-03-06 14:30 UTC by Stefan Behte (RETIRED)
Modified: 2012-02-25 01:52 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2010-03-06 14:30:39 UTC
CVE-2009-3369 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3369):
  CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in
  use in a multi-user environment, does not restrict users from the
  ClientNameAlias function, which allows remote authenticated users to
  read and write sensitive files by modifying ClientNameAlias to match
  another system, then initiating a backup or restore.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2010-03-06 14:31:41 UTC
Hi, we have the ancient version 2.1.2-r1, can you quickly advise if this bug is  relevant for us, too?
Comment 2 Dmitri Pogosian 2010-07-28 05:13:31 UTC
In ebuild for version 3.1.0  discussed  in Bug#: 287133, this vulnerability seems have been fixed.  Unfortunately this ebuild has not yet made into the tree after almost a year of discussion.
Comment 3 Antek Grzymała (antoszka) 2010-08-03 12:19:19 UTC
Yeah, 3.2.0 has been released in the meantime as well.
Comment 4 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-02-19 10:43:48 UTC
There are some patches, and maybe there is a more recent upstream release that fixes it.

Maintainers, your move. This bug is now overdue. Maybe we should mask the package?
Comment 5 Patrick Lauer gentoo-dev 2011-08-29 12:06:29 UTC
3.2.1 in tree, feel free to proceed as needed.
Comment 6 Tim Sammut (RETIRED) gentoo-dev 2011-08-29 13:55:49 UTC
Thanks, Patrick.

Arches, please test and mark stable:
=app-backup/backuppc-3.2.1
Target keywords : "amd64"
Comment 7 Agostino Sarubbo gentoo-dev 2011-08-29 15:19:19 UTC
only warning about -c/--chuid but amd64 ok.
Comment 8 Ian Delaney (RETIRED) gentoo-dev 2011-08-30 18:01:40 UTC
amd64:

ditto Ago
Comment 9 Ian Delaney (RETIRED) gentoo-dev 2011-09-01 14:28:25 UTC
version 3.2.1-r2 is present in the tree
Comment 10 Tomáš "tpruzina" Pružina (amd64 [ex]AT) 2011-09-01 15:52:31 UTC
amd64 ok
Comment 11 Tony Vroon (RETIRED) gentoo-dev 2011-09-01 16:17:44 UTC
+  01 Sep 2011; Tony Vroon <chainsaw@gentoo.org> backuppc-3.2.1-r2.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo, Ian
+  "idella4" Delaney & Tomáš "Mepho" Pružina in security bug #308013 filed by
+  Stefan "craig" Behte.
Comment 12 Tim Sammut (RETIRED) gentoo-dev 2011-09-01 17:55:29 UTC
Thanks, folks. GLSA vote: yes.
Comment 13 Tim Sammut (RETIRED) gentoo-dev 2011-10-02 04:12:44 UTC
Looks like 3.2.1 also fixed a XSS vulnerability. Upstream diff at http://backuppc.cvs.sourceforge.net/viewvc/backuppc/BackupPC/lib/BackupPC/CGI/Browse.pm?r1=1.23&r2=1.24.
Comment 14 Tobias Heinlein (RETIRED) gentoo-dev 2011-10-08 22:35:02 UTC
Re-rated C4 due to the specific requirements, closing [noglsa].
Comment 15 GLSAMaker/CVETool Bot gentoo-dev 2012-02-25 01:52:45 UTC
CVE-2011-3361 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3361):
  Cross-site scripting (XSS) vulnerability in CGI/Browse.pm in BackupPC 3.2.0
  and possibly other versions before 3.2.1 allows remote attackers to inject
  arbitrary web script or HTML via the num parameter in a browse action to
  index.cgi.