From 0ee61b1ed441ab2406d6bf942ad340257740ad9a Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Mon, 26 Feb 2024 12:53:03 +0000 Subject: [ GLSA 202402-32 ] btrbk: Remote Code Execution Bug: https://bugs.gentoo.org/806962 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202402-32.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 glsa-202402-32.xml (limited to 'glsa-202402-32.xml') diff --git a/glsa-202402-32.xml b/glsa-202402-32.xml new file mode 100644 index 00000000..e5b64a52 --- /dev/null +++ b/glsa-202402-32.xml @@ -0,0 +1,42 @@ + + + + btrbk: Remote Code Execution + A vulnerability has been discovered in btrbk which can lead to remote code execution. + btrbk + 2024-02-26 + 2024-02-26 + 806962 + remote + + + 0.31.2 + 0.31.2 + + + +

btrbk is a backup tool for btrfs subvolumes, taking advantage of btrfs specific capabilities to create atomic snapshots and transfer them incrementally to your backup locations.

+
+ +

A vulnerability has been discovered in btrbk. Please review the CVE identifier referenced below for details.

+
+ +

Specialy crafted commands may be executed without being propely checked. Applies to remote hosts filtering ssh commands using ssh_filter_btrbk.sh in authorized_keys.

+
+ +

There is no known workaround at this time.

+
+ +

All btrbk users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-backup/btrbk-0.31.2" + +
+ + CVE-2021-38173 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad