CVE-2009-3611
Last modified
CVE-2009-3611 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Le-Web | Backintime | 0.9.26 |
| Fedoraproject | Fedora | 10 |
| Fedoraproject | Fedora | 11 |
References
- http://bugs.gentoo.org/show_bug.cgi?id=289047Issue Tracking, Patch
- https://bugs.launchpad.net/ubuntu/+source/backintime/+bug/434256Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=520210Issue Tracking
- http://bugs.gentoo.org/show_bug.cgi?id=289047Issue Tracking, Patch
- https://bugs.launchpad.net/ubuntu/+source/backintime/+bug/434256Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=520210Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-3611?
How severe is CVE-2009-3611?
How do I fix CVE-2009-3611?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-3605Multiple integer overflows in Poppler 0.10.5 and earlier all…
- CVE-2009-3606Integer overflow in the PSOutputDev::doImageL1Sep function i…
- CVE-2009-3607Integer overflow in the create_surface_from_thumbnail_data f…
- CVE-2009-3608Integer overflow in the ObjectStream::ObjectStream function …
- CVE-2009-3609Integer overflow in the ImageStream::ImageStream function in…
- CVE-2009-3610Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2009-3612The tcf_fill_node function in net/sched/cls_api.c in the net…
- CVE-2009-3613The swiotlb functionality in the r8169 driver in drivers/net…
- CVE-2009-3614liboping 1.3.2 allows users reading arbitrary files upon the…3.3
- CVE-2009-3615The OSCAR protocol plugin in libpurple in Pidgin before 2.6.…
- CVE-2009-3616Multiple use-after-free vulnerabilities in vnc.c in the VNC …9.9
- CVE-2009-3617Format string vulnerability in the AbstractCommand::onAbort …
Are you affected by CVE-2009-3611?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
