Vulnerability in Timeshift that allows privilege escalation in the system

In the application Timeshift identified vulnerability (CVE-2020-10174), allowing a local user to execute code with root privileges. Timeshift is a backup system that uses rsync with hard link creation or Btrfs snapshots to implement functionality similar to System Restore in Windows and Time Machine in macOS. The program is included in the repositories of many distributions and is used by default in PCLinuxOS and Linux Mint. The vulnerability has been fixed in the release Timeshift 20.03.

The issue is caused by improper handling of the public directory /tmp. During the backup creation, the program creates the directory /tmp/timeshift, within which it generates a subdirectory with a random name containing a shell script with commands that run with root privileges. The subdirectory containing the script has an unpredictable name, but /tmp/timeshift itself is predictable and is not checked for replacement or creation of a symbolic link instead. An attacker can create the directory /tmp/timeshift under their name, then monitor the appearance of the subdirectory and replace this subdirectory and the file within it. During its operation, Timeshift will execute a script not generated by the program, but a file swapped by the attacker with root privileges.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster