Your message dated Fri, 09 Oct 2009 19:32:04 +0000
with message-id <e1mwlc8-0006uv...@ries.debian.org>
and subject line Bug#542218: fixed in backuppc 3.1.0-8
has caused the Debian Bug report #542218,
regarding backuppc: Security hole when using rsync and multiple users
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
542218: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=542218
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: backuppc
Version: 3.1.0-4
Severity: critical
Tags: security
Justification: root security hole


When using an SSH key and Rsync with BackupPC on a system with multiple users, 
Users (as opposed to admins) have the ability to change the ClientNameAlias on 
machines they are listed as owning.
As BackupPC user has one ssh key, which can be in the authorized keys of many 
machines (often as root), this allows a user to backup from and restore to any 
machines that key gives access to, by changing the ClientNameAlias to the 
target machine and initiating a backup.

I've just tested this, and as an unpriviledged user was able to change backing 
up /scratch on my desktop to /etc on a server and then read /etc/shadow from 
the server.
Whilst I haven't tested this, I see no reason I couldn't restore to the server 
as well, thus changing arbitrary files as root (and gaining root access).




-- System Information:
Debian Release: 5.0.1
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.26-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages backuppc depends on:
ii  adduser                  3.110           add and remove users and groups
ii  apache2                  2.2.9-10+lenny2 Apache HTTP Server metapackage
ii  apache2-mpm-worker [http 2.2.9-10+lenny2 Apache HTTP Server - high speed th
ii  bzip2                    1.0.5-1         high-quality block-sorting file co
ii  debconf [debconf-2.0]    1.5.24          Debian configuration management sy
ii  dpkg                     1.14.25         Debian package management system
ii  libarchive-zip-perl      1.18-1          Module for manipulation of ZIP arc
ii  libcompress-zlib-perl    2.012-1         Perl module for creation and manip
ii  perl [libdigest-md5-perl 5.10.0-19       Larry Wall's Practical Extraction 
ii  perl-suid                5.10.0-19       Runs setuid Perl scripts
ii  samba-common             2:3.2.5-4lenny2 Samba common files used by both th
ii  smbclient                2:3.2.5-4lenny2 a LanManager-like simple client fo
ii  tar                      1.20-1          GNU version of the tar archiving u

Versions of packages backuppc recommends:
ii  libfile-rsyncp-perl          0.68-1.1+b1 A perl based implementation of an 
ii  openssh-client [ssh-client]  1:5.1p1-5   secure shell client, an rlogin/rsh
ii  postfix [mail-transport-agen 2.5.5-1.1   High-performance mail transport ag
ii  rrdtool                      1.3.1-4     Time-series data storage and displ
ii  rsync                        3.0.3-2     fast remote file copy program (lik

Versions of packages backuppc suggests:
pn  par2                          <none>     (no description available)
ii  w3m [www-browser]             0.5.2-2+b1 WWW browsable pager with excellent

-- debconf information excluded



--- End Message ---
--- Begin Message ---
Source: backuppc
Source-Version: 3.1.0-8

We believe that the bug you reported is fixed in the latest version of
backuppc, which is due to be installed in the Debian FTP archive:

backuppc_3.1.0-8.diff.gz
  to pool/main/b/backuppc/backuppc_3.1.0-8.diff.gz
backuppc_3.1.0-8.dsc
  to pool/main/b/backuppc/backuppc_3.1.0-8.dsc
backuppc_3.1.0-8_all.deb
  to pool/main/b/backuppc/backuppc_3.1.0-8_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 542...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ludovic Drolez <ldro...@debian.org> (supplier of updated backuppc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Fri, 09 Oct 2009 20:58:32 +0200
Source: backuppc
Binary: backuppc
Architecture: source all
Version: 3.1.0-8
Distribution: unstable
Urgency: high
Maintainer: Ludovic Drolez <ldro...@debian.org>
Changed-By: Ludovic Drolez <ldro...@debian.org>
Description: 
 backuppc   - high-performance, enterprise-grade system for backing up PCs
Closes: 542218
Changes: 
 backuppc (3.1.0-8) unstable; urgency=high
 .
   * Really fix the alias bug. Closes: #542218
   * Small init.d file fix
Checksums-Sha1: 
 cd2fe86b1a01d088b758a987e4fb63ff3f6a61a3 1009 backuppc_3.1.0-8.dsc
 b605c476e037d0df09c4f3bdc17d292a142b2ae8 25811 backuppc_3.1.0-8.diff.gz
 43cd090c5f4894a17142d0f4de6f13f4f77a53c6 564508 backuppc_3.1.0-8_all.deb
Checksums-Sha256: 
 e598edd195e2e241a83f57bbe52ca7caf3de4e595b6c146f968edcff480c0cf2 1009 
backuppc_3.1.0-8.dsc
 f8bd7fc0dc2297658d07274f832c1e1bba5ece70c9ba11ab93e12c9b740eb94b 25811 
backuppc_3.1.0-8.diff.gz
 f761bc6ceb145b8822fdea1cc9e3d3cf16b5a526d7b6e2a842b81330004248cf 564508 
backuppc_3.1.0-8_all.deb
Files: 
 5480bdf088cef89045ad1f01bba54e92 1009 utils optional backuppc_3.1.0-8.dsc
 cf713bee0c011d1d35fcb94aab4f21f8 25811 utils optional backuppc_3.1.0-8.diff.gz
 6bcfc0e4c3ba1642271b11dc0b656e0b 564508 utils optional backuppc_3.1.0-8_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkrPi8EACgkQsRlQAP1GppgYrQCfSn0mMsJ4X1pKE45/GvglSNsl
DygAn3mO5ZSUAUlRtTdLLaPfwkizYMHc
=xUZ5
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to