CVE-2017-16667
backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to some parts of file paths being executed as shell commands within an os.system call in…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.46%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to some parts of file paths being executed as shell commands within an os.system call in qt4/plugins/notifyplugin.py. This could allow an attacker to craft an unreadable file with a specific name to run arbitrary shell commands.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.46% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- backintime project/backintime
- Source
- cve@mitre.org
References
- https://github.com/bit-team/backintime/commit/cef81d0da93ff601252607df3db1a48f7f6f01b3Patch, Third Party Advisory
- https://github.com/bit-team/backintime/issues/834Third Party Advisory
- https://github.com/bit-team/backintime/releases/tag/v1.1.24Release Notes, Third Party Advisory
- https://security.gentoo.org/glsa/201801-06Third Party Advisory
- https://github.com/bit-team/backintime/commit/cef81d0da93ff601252607df3db1a48f7f6f01b3Patch, Third Party Advisory
- https://github.com/bit-team/backintime/issues/834Third Party Advisory
- https://github.com/bit-team/backintime/releases/tag/v1.1.24Release Notes, Third Party Advisory
- https://security.gentoo.org/glsa/201801-06Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.