backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to some parts of file paths being executed as shell commands within an os.system call in qt4/plugins/notifyplugin.py. This could allow an attacker to craft an unreadable file with a specific name to run arbitrary shell commands.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade backintime | Jul 30, 2024 | Nov 8, 2017 |
| Gentoo Linux | — | Upgrade app-backup/backintime. | Jan 8, 2018 | Nov 8, 2017 |
| Suse | — | Upgrade backintimeUpgrade backintime-langUpgrade backintime-qt4 | Nov 27, 2017 | Nov 8, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Nov 8, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub