Unrated severityNVD Advisory· Published Sep 24, 2009· Updated Apr 23, 2026
CVE-2009-3369
CVE-2009-3369
Description
CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/36393nvdVendor Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvd
- osvdb.org/57236nvd
- secunia.com/advisories/37161nvd
- bugzilla.redhat.com/show_bug.cginvd
- www.redhat.com/archives/fedora-package-announce/2009-October/msg00694.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-October/msg00729.htmlnvd
News mentions
0No linked articles in our index yet.