Backup Manager · Backup Manager · CVE-2005-1856
**Name of the Vulnerable Software and Affected Versions**
backup-manager versions 0.5.8 and earlier
**Description**
The issue concerns the CD-burning feature in backup-manager, which uses a fixed filename in a world-writable directory for logging. This allows local users to overwrite files via a symlink attack.
**Recommendations**
For backup-manager versions 0.5.8 and earlier, consider restricting write access to the logging directory to prevent file overwrites until a patch is available. As a temporary workaround, avoid using the CD-burning feature in backup-manager until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.