Bug#304366: rsnapshot: chown() follow symlink vulnerability

2005-04-12 Thread Christoph Wegscheider
tags 304366 pending thanks On Tue, Apr 12, 2005 at 07:37:29PM +0200, Moritz Muehlenhoff wrote: > Quoting a recent rsnapshot security advisory fully available at > http://www.rsnapshot.org/security/2005/001.html: > 1.2.1 fixes this issue. The upstream author has informed me in advance of that secu

Bug#304366: rsnapshot: chown() follow symlink vulnerability

2005-04-12 Thread Moritz Muehlenhoff
Package: rsnapshot Severity: important Tags: security Quoting a recent rsnapshot security advisory fully available at http://www.rsnapshot.org/security/2005/001.html: The copy_symlink() subroutine in rsnapshot incorrectly changes file ownership on the files pointed to by symlinks, not on the syml