lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by an unprivileged account, which could potentially be used to install a Trojan horse backup.pl script that is later executed by root. Similar problems with the ownership/permissions of other files may be present as well.
| Software | From | Fixed in |
|---|---|---|
| ipfire / ipfire | 2.25-core_update142 | 2.25-core_update142.x |
| ipfire / ipfire | 2.25-core_update143 | 2.25-core_update143.x |
| ipfire / ipfire | 2.25-core_update144 | 2.25-core_update144.x |
| ipfire / ipfire | 2.25-core_update145 | 2.25-core_update145.x |
| ipfire / ipfire | 2.25-core_update146 | 2.25-core_update146.x |
| ipfire / ipfire | 2.25-core_update147 | 2.25-core_update147.x |
| ipfire / ipfire | 2.25-core_update148 | 2.25-core_update148.x |
| ipfire / ipfire | 2.25-core_update149 | 2.25-core_update149.x |
| ipfire / ipfire | 2.25-core_update150 | 2.25-core_update150.x |
| ipfire / ipfire | 2.25-core_update151 | 2.25-core_update151.x |
| ipfire / ipfire | 2.25-core_update152 | 2.25-core_update152.x |
| ipfire / ipfire | 2.25-core_update155 | 2.25-core_update155.x |
| ipfire / ipfire | 2.25-core_update156 | 2.25-core_update156.x |
| ipfire / ipfire | 2.25-core_update141 | 2.25-core_update141.x |
| ipfire / ipfire | - | 2.25 |