CVE Vulnerabilities

CVE-2016-10099

Published: Jan 02, 2017 | Modified: Jul 12, 2017
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

Borg (aka BorgBackup) before 1.0.9 has a flaw in the cryptographic protocol used to authenticate the manifest (list of archives), potentially allowing an attacker to spoof the list of archives.

Affected Software

Name Vendor Start Version End Version
Borg Borg_project * 1.0.8 (including)
Borgbackup Ubuntu artful *
Borgbackup Ubuntu yakkety *
Borgbackup Ubuntu zesty *

References