PT-2021-20131 · Ipfire · Ipfire

Published

2021-06-09

·

Updated

2022-07-12

·

CVE-2021-33393

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IPFire version 2.25-core155
Description The issue is related to the ownership of certain files, specifically /var/ipfire/backup/bin/backup.pl, which may not be owned by the root account. This could potentially allow an unprivileged account to install a malicious script that is later executed by root. Similar problems with the ownership and permissions of other files may also be present.
Recommendations For IPFire version 2.25-core155, ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account to prevent potential exploitation. As a temporary workaround, consider restricting access to the backup.pl script until the issue is resolved. Additionally, review the ownership and permissions of other files to identify and address any similar problems.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-33393

Affected Products

Ipfire