DEBIAN-CVE-2025-68462

Source
https://security-tracker.debian.org/tracker/CVE-2025-68462
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68462.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2025-68462
Upstream
  • CVE-2025-68462
Published
2025-12-18T06:15:50Z
Modified
2026-09-01T20:05:57Z
Severity
  • 3.2 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Freedombox before 25.17.1 does not set proper permissions for the backups-data directory, allowing the reading of dump files of databases.

References

Affected packages

Debian:12 / freedombox

Package

Name
freedombox
Purl
pkg:deb/debian/freedombox?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

23.*
23.6.2
23.6.2+deb12u1
23.7
23.8
23.9
23.10
23.11
23.12~bpo12+1
23.12
23.13~bpo12+1
23.13
23.14~bpo12+1
23.14
23.15~bpo12+1
23.15
23.16~bpo12+1
23.16
23.17~bpo12+1
23.17
23.18~bpo12+1
23.18
23.19~bpo12+1
23.19
23.20~bpo12+1
23.20
23.21~bpo12+1
23.21
24.*
24.1~bpo12+1
24.1
24.2~bpo12+1
24.2
24.3~bpo12+1
24.3
24.4~bpo12+1
24.4
24.5~bpo12+1
24.5
24.6
24.7~bpo12+1
24.7
24.8~bpo12+1
24.8
24.9~bpo12+1
24.9
24.10~bpo12+1
24.10
24.11~bpo12+1
24.11
24.12~bpo12+1
24.12
24.13~bpo12+1
24.13
24.14~bpo12+1
24.14
24.15~bpo12+1
24.15
24.16~bpo12+1
24.16
24.17~bpo12+1
24.17
24.18~bpo12+1
24.18
24.19
24.20
24.20.1~bpo12+1
24.20.1
24.21~bpo12+1
24.21
24.22~bpo12+1
24.22
24.23~bpo12+1
24.23
24.24~bpo12+1
24.24
24.25~bpo12+1
24.25
24.26
24.26.1~bpo12+1
24.26.1
25.*
25.1~bpo12+1
25.1
25.2
25.3
25.3.1~bpo12+1
25.3.1
25.4
25.4.1~bpo12+1
25.4.1
25.5~bpo12+1
25.5
25.6~bpo12+1
25.6
25.7~bpo12+1
25.7
25.8~bpo12+1
25.8
25.9~bpo12+1
25.9
25.9.1~bpo12+1
25.9.1
25.9.2~bpo12+1
25.9.2
25.9.3~bpo12+1
25.9.3~bpo12+2
25.9.3
25.9.4
25.10~bpo13+1
25.10
25.11~bpo13+1
25.11
25.12~bpo13+1
25.12
25.13~bpo13+1
25.13
25.13.1~bpo13+1
25.13.1
25.14~bpo13+1
25.14
25.15~bpo13+1
25.15
25.16~bpo13+1
25.16
25.17~bpo13+1
25.17
25.17.1~bpo13+1
25.17.1
26.*
26.1~bpo13+1
26.1
26.2~bpo13+1
26.2
26.3
26.4~bpo13+1
26.4
26.4.1
26.4.2~bpo13+1
26.4.2
26.5
26.5.1~bpo13+1
26.5.1
26.6~bpo13+1
26.6
26.7
26.7.1~bpo13+1
26.7.1
26.8~bpo13+1
26.8
26.9
26.9.1~bpo13+1
26.9.1
26.10~bpo13+1
26.10
26.11
26.11.1~bpo13+1
26.11.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68462.json"

Debian:13 / freedombox

Package

Name
freedombox
Purl
pkg:deb/debian/freedombox?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
25.9.3+deb13u1

Affected versions

25.*
25.9.3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68462.json"

Debian:14 / freedombox

Package

Name
freedombox
Purl
pkg:deb/debian/freedombox?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
25.17.1

Affected versions

25.*
25.9.3
25.9.4
25.10~bpo13+1
25.10
25.11~bpo13+1
25.11
25.12~bpo13+1
25.12
25.13~bpo13+1
25.13
25.13.1~bpo13+1
25.13.1
25.14~bpo13+1
25.14
25.15~bpo13+1
25.15
25.16~bpo13+1
25.16
25.17~bpo13+1
25.17
25.17.1~bpo13+1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68462.json"