Package: rsnapshot Severity: important Tags: security Quoting a recent rsnapshot security advisory fully available at http://www.rsnapshot.org/security/2005/001.html:
The copy_symlink() subroutine in rsnapshot incorrectly changes file ownership on the files pointed to by symlinks, not on the symlinks themselves. This would allow, under certain circumstances, an arbitrary user to take ownership of a file on the main filesystem. 1.2.1 fixes this issue. Cheers, Moritz rsnapshot incorrectly changes file ownerships on files pointed to through symlinks -- System Information: Debian Release: 3.1 APT prefers unstable APT policy: (500, 'unstable') Architecture: i386 (i686) Kernel: Linux 2.6.11 Locale: LANG=C, [EMAIL PROTECTED] (charmap=ISO-8859-15) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]