MEDIUM · 4.6

CVE-2005-3148

StoreBackup before 1.19 does not properly set the uid and guid for symbolic links (1) that are backed up by storeBackup.pl, or (2) recovered by storeBackupRecover.pl, which could cause files to be res...

Vulnerability Description

StoreBackup before 1.19 does not properly set the uid and guid for symbolic links (1) that are backed up by storeBackup.pl, or (2) recovered by storeBackupRecover.pl, which could cause files to be restored with incorrect ownership.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
StorebackupStorebackup1.1
SuseSuse LinuxAll versions

References

FAQ

What is CVE-2005-3148?

CVE-2005-3148 is a vulnerability with a CVSS score of 4.6 (MEDIUM). StoreBackup before 1.19 does not properly set the uid and guid for symbolic links (1) that are backed up by storeBackup.pl, or (2) recovered by storeBackupRecover.pl, which could cause files to be res...

How severe is CVE-2005-3148?

CVE-2005-3148 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-3148?

Check the references section above for vendor advisories and patch information. Affected products include: Storebackup Storebackup, Suse Suse Linux.