Vulnerability in Timeshift allowing privilege escalation

Rakenduses Timeshift tuvastatud haavatavus (CVE-2020-10174), allowing a local user to execute code with root privileges. Timeshift is a backup system utilizing rsync with hard link establishment or Btrfs snapshots to provide functionality similar to System Restore in Windows and Time Machine in macOS. The program is included in the repositories of many distributions and is used by default in PCLinuxOS and Linux Mint. The vulnerability is fixed in the release Timeshift 20.03.

The issue is caused by improper handling of the public directory /tmp. When creating a backup, the program creates a directory /tmp/timeshift, within which a subdirectory with a random name is created, containing a shell script with commands executed with root privileges. The subdirectory with the script has a unpredictable name, but the /tmp/timeshift itself is predictable and not checked for substitution or creation of a symbolic link instead. An attacker can create a directory /tmp/timeshift in their name, after which they can track the appearance of the subdirectory and substitute this subdirectory and the file within it. During its operation, Timeshift will execute not the script generated by the program, but the file replaced by the attacker with root privileges.

Allikas: opennet.ru

Osta usaldusväärne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid 🔥 Osta usaldusväärne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid | ProHoster