Bug#542218: Acknowledgement (backuppc: Security hole when using rsync and multiple users)

2009-08-20 Thread David Ambrose-Griffith
ClientNameAlias from the list specified in CgiUserConfigEdit, users cannot change hostnames, thus closing this hole. Regards, David Ambrose-Griffith -- David Ambrose-Griffith - d.e.ambrose-griff...@durham.ac.uk Assistant Systems Programmer, IPPP, Department of Physics, Durham University, Science

Bug#542218: backuppc: Security hole when using rsync and multiple users

2009-08-18 Thread David Ambrose-Griffith
Package: backuppc Version: 3.1.0-4 Severity: critical Tags: security Justification: root security hole When using an SSH key and Rsync with BackupPC on a system with multiple users, Users (as opposed to admins) have the ability to change the ClientNameAlias on machines they are listed as owning