Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 9: DLA-2353-1 Critical: Bacula Denial Of Service Issue

An issue has been found in bacula, a network backup service. By sending oversized digest strings a malicious client can cause a heap overflow in the director's memory which results in a denial of service. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2353-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz August 29, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : bacula Version : 7.4.4+dfsg-6+deb9u2 CVE ID : CVE-2020-11061 Debian Bug : An issue has been found in bacula, a network backup service. By sending oversized digest strings a malicious client can cause a heap overflow in the director's memory which results in a denial of service. For Debian 9 stretch, this problem has been fixed in version 7.4.4+dfsg-6+deb9u2. We recommend that you upgrade your bacula packages. For the detailed security status of bacula please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/bacula Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A critical vulnerability detected in bacula enables denial of service due to heap overflow triggered by excessively large strings. Immediate upgrade is advised.. bacula, debian LTS, denial of service, memory overflow, security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 29, 2020 Critical Debian LTS
91

Gentoo: GLSA-201405-11 Low: Bacula Information Disclosure Risk

A vulnerability in Bacula may allow remote attackers to obtain sensitive information.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201405-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Bacula: Information disclosure Date: May 17, 2014 Bugs: #434878 ID: 201405-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in Bacula may allow remote attackers to obtain sensitive information. Background ========= Bacula is a network based backup suite. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-backup/bacula < 5.2.12 > = 5.2.12 Description ========== Bacula does not properly enforce console access control lists. Impact ===== A remote authenticated attacker may be able to bypass restrictions to obtain sensitive information. Workaround ========= There is no known workaround at this time. Resolution ========= All Bacula users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-backup/bacula-5.2.12" References ========= [ 1 ] CVE-2012-4430 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4430 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201405-11 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressedto This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2014 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . A vulnerability in Bacula presents a risk of unauthorized access to confidential data on Gentoo platforms. The severity is rated as low, but updating is advised.. bacula vulnerability, gentoo security, information disclosure, remote access threat. . Severity: Low. LinuxSecurity.com Team

Calendar 2 May 17, 2014 Low Gentoo
87

Debian: DSA-2558-1 Critical: Bacula Information Exposure

It was discovered that bacula, a network backup service, does not properly enforce console ACLs. This could allow information about resources to be dumped by an otherwise-restricted client. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2558-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Raphael Geissert October 08, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : bacula Vulnerability : information disclosure Problem type : local (remote) Debian-specific: no CVE ID : CVE-2012-4430 It was discovered that bacula, a network backup service, does not properly enforce console ACLs. This could allow information about resources to be dumped by an otherwise-restricted client. For the stable distribution (squeeze), this problem has been fixed in version 5.0.2-2.2+squeeze1. For the testing distribution (wheezy), this problem will be fixed soon. For the unstable distribution (sid), this problem has been fixed in version 5.2.6+dfsg-4. We recommend that you upgrade your bacula packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance Bacula to eliminate data exposure risks stemming from insufficient ACL implementation in Debian. Urgent patches released immediately.. Bacula Security, ACL Enforcement, Information Exposure, Debian Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 08, 2012 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here