The CD-burning feature in backup-manager 0.5.8 and earlier uses a fixed filename in a world-writable directory for logging, which allows local users to overwrite files via a symlink attack.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Backup_manager | Sukria | 0.5.6 (including) | 0.5.6 (including) |
| Backup_manager | Sukria | 0.5.7 (including) | 0.5.7 (including) |