An issue has been found in bacula, a network backup service. By sending oversized digest strings a malicious client can cause a heap overflow in the director's memory which results in a denial of service. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2353-1
A vulnerability in Bacula may allow remote attackers to obtain sensitive information.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201405-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Bacula: Information disclosure Date: May 17, 2014 Bugs: #434878 ID: 201405-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in Bacula may allow remote attackers to obtain sensitive information. Background ========= Bacula is a network based backup suite. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-backup/bacula < 5.2.12 > = 5.2.12 Description ========== Bacula does not properly enforce console access control lists. Impact ===== A remote authenticated attacker may be able to bypass restrictions to obtain sensitive information. Workaround ========= There is no known workaround at this time. Resolution ========= All Bacula users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-backup/bacula-5.2.12" References ========= [ 1 ] CVE-2012-4430 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4430 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201405-11 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressedto
It was discovered that bacula, a network backup service, does not properly enforce console ACLs. This could allow information about resources to be dumped by an otherwise-restricted client. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2558-1
Get the latest Linux and open source security news straight to your inbox.