PT-2020-19350 · Storebackup+3 · Storebackup+3

Matthias Gerstner

·

Published

2020-01-21

·

Updated

2024-06-15

·

CVE-2020-7040

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions storeBackup versions 3.5 and earlier
Description The issue allows for symlink attacks, potentially leading to privilege escalation, as it relies on the /tmp/storeBackup.lock pathname. Local users can also create a plain file named /tmp/storeBackup.lock to block the use of storeBackup until an admin manually deletes that file.
Recommendations For storeBackup versions 3.5 and earlier, consider restricting access to the /tmp/storeBackup.lock file to prevent symlink attacks and privilege escalation. As a temporary workaround, monitor the /tmp directory for any suspicious files or symlinks named storeBackup.lock and remove them manually to ensure storeBackup functionality.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7040
DLA-2095-1
OPENSUSE-SU-2020:0119-1
OPENSUSE-SU-2020_0119-1
OPENSUSE-SU-2024:11410-1
USN-4508-1

Affected Products

Linuxmint
Suse
Ubuntu
Storebackup