- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201801-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Back In Time: Command injection Date: January 07, 2018 Bugs: #636974 ID: 201801-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A command injection vulnerability in 'Back in Time' may allow for the execution of arbitrary shell commands. Background ========== A simple backup tool for Linux, inspired by "flyback project". Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-backup/backintime < 1.1.24 >= 1.1.24 Description =========== 'Back in Time' did improper escaping/quoting of file paths used as arguments to the 'notify-send' command leading to some parts of file paths being executed as shell commands within an os.system call. Impact ====== A context-dependent attacker could execute arbitrary shell commands via a specially crafted file. Workaround ========== There is no known workaround at this time. Resolution ========== All 'Back In Time' users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=app-backup/backintime-1.1.24" References ========== [ 1 ] CVE-2017-16667 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-16667 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201801-06 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License =======