PT-2020-19350 · Storebackup+3 · Storebackup+3
Matthias Gerstner
·
Published
2020-01-21
·
Updated
2024-06-15
·
CVE-2020-7040
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
storeBackup versions 3.5 and earlier
Description
The issue allows for symlink attacks, potentially leading to privilege escalation, as it relies on the /tmp/storeBackup.lock pathname. Local users can also create a plain file named /tmp/storeBackup.lock to block the use of storeBackup until an admin manually deletes that file.
Recommendations
For storeBackup versions 3.5 and earlier, consider restricting access to the /tmp/storeBackup.lock file to prevent symlink attacks and privilege escalation. As a temporary workaround, monitor the /tmp directory for any suspicious files or symlinks named storeBackup.lock and remove them manually to ensure storeBackup functionality.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Suse
Ubuntu
Storebackup