← Back

Storebackup

storebackup

Vendor: Storebackup • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
DebianOpensuse+1 more
5Backports Sle
Debian LinuxLeap+2 more
Nov 21, 2024
Jan 21, 2020
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeB...Show more
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin manually deletes that file.)Show less
2Storebackup
Suse
2Storebackup
Suse Linux
Apr 16, 2026
Oct 5, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
StoreBackup before 1.19 does not properly set the uid and guid for symbolic links (1) that are backed up by storeBackup.pl, or (2) recovered by storeBackupRecover.pl, which could cause files to be restored with incorrect...Show more
StoreBackup before 1.19 does not properly set the uid and guid for symbolic links (1) that are backed up by storeBackup.pl, or (2) recovered by storeBackupRecover.pl, which could cause files to be restored with incorrect ownership.Show less
2Storebackup
Suse
2Storebackup
Suse Linux
Apr 16, 2026
Oct 5, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
StoreBackup before 1.19 creates the backup root with world-readable permissions, which allows local users to obtain sensitive information.
2Storebackup
Suse
2Storebackup
Suse Linux
Apr 16, 2026
Oct 5, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
StoreBackup before 1.19 allows local users to perform unauthorized operations on arbitrary files via a symlink attack on temporary files.