Rsnapshot contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is due to an error in the "copy_symlink()" function where file permissions for symlinks are incorrectly set on the original file. This flaw may allow an attacker to take ownership of arbitrary files by placing a malicious symlink in a directory being backed up, resulting in a loss of integrity.
Classification
Location:
Local Access Required
Attack Type:
Race Condition
Impact:
Loss of Integrity
Disclosure:
OSVDB Verified,
Vendor Verified
Solution
Upgrade to version 1.2.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.