CVE-2016-10099

Borg (aka BorgBackup) before 1.0.9 has a flaw in the cryptographic protocol used to authenticate the manifest (list of archives), potentially allowing an attacker to spoof the list of archives.
Configurations

Configuration 1 (hide)

cpe:2.3:a:borg_project:borg:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:43

Type Values Removed Values Added
References () http://borgbackup.readthedocs.io/en/stable/changes.html#pre-1-0-9-manifest-spoofing-vulnerability - Mitigation, Vendor Advisory () http://borgbackup.readthedocs.io/en/stable/changes.html#pre-1-0-9-manifest-spoofing-vulnerability - Mitigation, Vendor Advisory
References () http://www.securityfocus.com/bid/95205 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/95205 - Third Party Advisory, VDB Entry

Information

Published : 2017-01-02 21:59

Updated : 2024-11-21 02:43


NVD link : CVE-2016-10099

Mitre link : CVE-2016-10099

CVE.ORG link : CVE-2016-10099


JSON object : View

Products Affected

borg_project

  • borg
CWE
CWE-310

Cryptographic Issues