CVE-2025-68462

NameCVE-2025-68462
DescriptionFreedombox before 25.17.1 does not set proper permissions for the backups-data directory, allowing the reading of dump files of databases.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freedombox (PTS)bullseye21.4.4vulnerable
bookworm23.6.2+deb12u1vulnerable
trixie25.9.3vulnerable
forky, sid25.17.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freedomboxsource(unstable)25.17.1

Notes

[trixie] - freedombox <no-dsa> (Minor issue)
[bookworm] - freedombox <no-dsa> (Minor issue)
Fixed by: https://salsa.debian.org/freedombox-team/freedombox/-/commit/8ba444990b4af6eec4b6b2b26482b107d7ff1229 (v25.17.1)
https://salsa.debian.org/freedombox-team/freedombox/-/issues/2554 (not public)

Search for package or bug name: Reporting problems