lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by an unprivileged account, which could potentially be used to install a Trojan horse backup.pl script that is later executed by root. Similar problems with the ownership/permissions of other files may be present as well.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ipfire | Ipfire | * | 2.25 (excluding) |
Ipfire | Ipfire | 2.25-core_update141 (including) | 2.25-core_update141 (including) |
Ipfire | Ipfire | 2.25-core_update142 (including) | 2.25-core_update142 (including) |
Ipfire | Ipfire | 2.25-core_update143 (including) | 2.25-core_update143 (including) |
Ipfire | Ipfire | 2.25-core_update144 (including) | 2.25-core_update144 (including) |
Ipfire | Ipfire | 2.25-core_update145 (including) | 2.25-core_update145 (including) |
Ipfire | Ipfire | 2.25-core_update146 (including) | 2.25-core_update146 (including) |
Ipfire | Ipfire | 2.25-core_update147 (including) | 2.25-core_update147 (including) |
Ipfire | Ipfire | 2.25-core_update148 (including) | 2.25-core_update148 (including) |
Ipfire | Ipfire | 2.25-core_update149 (including) | 2.25-core_update149 (including) |
Ipfire | Ipfire | 2.25-core_update150 (including) | 2.25-core_update150 (including) |
Ipfire | Ipfire | 2.25-core_update151 (including) | 2.25-core_update151 (including) |
Ipfire | Ipfire | 2.25-core_update152 (including) | 2.25-core_update152 (including) |
Ipfire | Ipfire | 2.25-core_update155 (including) | 2.25-core_update155 (including) |
Ipfire | Ipfire | 2.25-core_update156 (including) | 2.25-core_update156 (including) |