CVE-2017-7572

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-7572
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7572.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-7572
Downstream
Related
Published
2017-04-06T18:59:00Z
Modified
2025-07-01T23:35:41.007561Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The _checkPolkitPrivilege function in serviceHelper.py in Back In Time (aka backintime) 1.1.18 and earlier uses a deprecated polkit authorization method (unix-process) that is subject to a race condition (time of check, time of use). With this authorization method, the owner of a process requesting a polkit operation is checked by polkitd via /proc/<pid>/status, by which time the requesting process may have been replaced by a different process with the same PID that has different privileges then the original requester.

References

Affected packages

Debian:11 / backintime

Package

Name
backintime
Purl
pkg:deb/debian/backintime?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.12-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / backintime

Package

Name
backintime
Purl
pkg:deb/debian/backintime?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.12-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / backintime

Package

Name
backintime
Purl
pkg:deb/debian/backintime?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.12-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/bit-team/backintime

Affected ranges

Type
GIT
Repo
https://github.com/bit-team/backintime
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.7.4
v0.8.0
v0.8.12
v0.8.14
v0.8.16
v0.8.18
v0.8.20
v0.8.8
v0.9.0
v0.9.10
v0.9.12
v0.9.14
v0.9.16
v0.9.18
v0.9.2
v0.9.20
v0.9.22
v0.9.24
v0.9.26
v0.9.4
v0.9.6
v0.9.8

v1.*

v1.0.0
v1.0.12
v1.0.14
v1.0.16
v1.0.18
v1.0.2
v1.0.20
v1.0.24
v1.0.28
v1.0.30
v1.0.36
v1.0.38
v1.0.4
v1.0.40
v1.0.6
v1.1.0
v1.1.10
v1.1.12
v1.1.2
v1.1.4
v1.1.6
v1.1.8