Your message dated Mon, 14 Sep 2009 12:32:07 +0000
with message-id <e1mnaj1-0006cw...@ries.debian.org>
and subject line Bug#542218: fixed in backuppc 3.1.0-7
has caused the Debian Bug report #542218,
regarding backuppc: Security hole when using rsync and multiple users
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
542218: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=542218
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: backuppc
Version: 3.1.0-4
Severity: critical
Tags: security
Justification: root security hole


When using an SSH key and Rsync with BackupPC on a system with multiple users, 
Users (as opposed to admins) have the ability to change the ClientNameAlias on 
machines they are listed as owning.
As BackupPC user has one ssh key, which can be in the authorized keys of many 
machines (often as root), this allows a user to backup from and restore to any 
machines that key gives access to, by changing the ClientNameAlias to the 
target machine and initiating a backup.

I've just tested this, and as an unpriviledged user was able to change backing 
up /scratch on my desktop to /etc on a server and then read /etc/shadow from 
the server.
Whilst I haven't tested this, I see no reason I couldn't restore to the server 
as well, thus changing arbitrary files as root (and gaining root access).




-- System Information:
Debian Release: 5.0.1
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.26-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages backuppc depends on:
ii  adduser                  3.110           add and remove users and groups
ii  apache2                  2.2.9-10+lenny2 Apache HTTP Server metapackage
ii  apache2-mpm-worker [http 2.2.9-10+lenny2 Apache HTTP Server - high speed th
ii  bzip2                    1.0.5-1         high-quality block-sorting file co
ii  debconf [debconf-2.0]    1.5.24          Debian configuration management sy
ii  dpkg                     1.14.25         Debian package management system
ii  libarchive-zip-perl      1.18-1          Module for manipulation of ZIP arc
ii  libcompress-zlib-perl    2.012-1         Perl module for creation and manip
ii  perl [libdigest-md5-perl 5.10.0-19       Larry Wall's Practical Extraction 
ii  perl-suid                5.10.0-19       Runs setuid Perl scripts
ii  samba-common             2:3.2.5-4lenny2 Samba common files used by both th
ii  smbclient                2:3.2.5-4lenny2 a LanManager-like simple client fo
ii  tar                      1.20-1          GNU version of the tar archiving u

Versions of packages backuppc recommends:
ii  libfile-rsyncp-perl          0.68-1.1+b1 A perl based implementation of an 
ii  openssh-client [ssh-client]  1:5.1p1-5   secure shell client, an rlogin/rsh
ii  postfix [mail-transport-agen 2.5.5-1.1   High-performance mail transport ag
ii  rrdtool                      1.3.1-4     Time-series data storage and displ
ii  rsync                        3.0.3-2     fast remote file copy program (lik

Versions of packages backuppc suggests:
pn  par2                          <none>     (no description available)
ii  w3m [www-browser]             0.5.2-2+b1 WWW browsable pager with excellent

-- debconf information excluded



--- End Message ---
--- Begin Message ---
Source: backuppc
Source-Version: 3.1.0-7

We believe that the bug you reported is fixed in the latest version of
backuppc, which is due to be installed in the Debian FTP archive:

backuppc_3.1.0-7.diff.gz
  to pool/main/b/backuppc/backuppc_3.1.0-7.diff.gz
backuppc_3.1.0-7.dsc
  to pool/main/b/backuppc/backuppc_3.1.0-7.dsc
backuppc_3.1.0-7_all.deb
  to pool/main/b/backuppc/backuppc_3.1.0-7_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 542...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ludovic Drolez <ldro...@debian.org> (supplier of updated backuppc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Tue, 01 Sep 2009 14:43:36 +0200
Source: backuppc
Binary: backuppc
Architecture: source all
Version: 3.1.0-7
Distribution: unstable
Urgency: high
Maintainer: Ludovic Drolez <ldro...@debian.org>
Changed-By: Ludovic Drolez <ldro...@debian.org>
Description: 
 backuppc   - high-performance, enterprise-grade system for backing up PCs
Closes: 483573 518554 542218
Changes: 
 backuppc (3.1.0-7) unstable; urgency=high
 .
   * Disable the modification of the alias for normal users. Closes: #542218
   * Recommends: libio-dirent-perl. Closes: #518554
   * manage config.pl with ucf. Closes: #483573
Checksums-Sha1: 
 034a9ebd207c0f143a5a106f9fdd83c5b4ba93aa 1009 backuppc_3.1.0-7.dsc
 d2181a8b005d967c8c8a25ac5c7362d59f258561 25650 backuppc_3.1.0-7.diff.gz
 3175c039c0dd4a8f199657e55de23dd18949bd89 564426 backuppc_3.1.0-7_all.deb
Checksums-Sha256: 
 51d00019f8e5e0b760542d66de5abc2181832318be5af13aca319cb6dcfcaf55 1009 
backuppc_3.1.0-7.dsc
 f2422574d5a2ee17b893f18ea88193548a3337438c3d58afdebd744a1129fd61 25650 
backuppc_3.1.0-7.diff.gz
 d0f9963811f493d2f663f091005eb36c9a75cd6c1862c118bc1b76a3baf0bcc6 564426 
backuppc_3.1.0-7_all.deb
Files: 
 5c643662a46797b44699758488707d13 1009 utils optional backuppc_3.1.0-7.dsc
 ccd2e6709ee89fa7644c7688ab10016b 25650 utils optional backuppc_3.1.0-7.diff.gz
 1b053d9e9900694ee0d0b1a1d8d88b42 564426 utils optional backuppc_3.1.0-7_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkquM2IACgkQsRlQAP1GppiifQCfaMsBng7RjB53TjXtPOGTDogX
6PcAoIuzEY4CsLJk8b+MfVA3zM1q48dl
=Nqbv
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to