OSVDB ID: 15420

Title: rsnapshot copy_symlink() Arbitrary File Ownership Modification

Info

Disclosure

Apr 09, 2005

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Rsnapshot contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is due to an error in the "copy_symlink()" function where file permissions for symlinks are incorrectly set on the original file. This flaw may allow an attacker to take ownership of arbitrary files by placing a malicious symlink in a directory being backed up, resulting in a loss of integrity.

Classification

Location: Local Access Required
Attack Type: Race Condition
Impact: Loss of Integrity
Disclosure: OSVDB Verified, Vendor Verified

Solution

Upgrade to version 1.2.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Nathan Rosenquist

rsnapshot

1.2.0
1.1.6

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/15420