The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bacula | Bacula | * | 5.2.11 (excluding) |
Bacula | Ubuntu | artful | * |
Bacula | Ubuntu | hardy | * |
Bacula | Ubuntu | lucid | * |
Bacula | Ubuntu | natty | * |
Bacula | Ubuntu | oneiric | * |
Bacula | Ubuntu | precise | * |
Bacula | Ubuntu | quantal | * |
Bacula | Ubuntu | raring | * |
Bacula | Ubuntu | saucy | * |
Bacula | Ubuntu | utopic | * |
Bacula | Ubuntu | vivid | * |
Bacula | Ubuntu | wily | * |
Bacula | Ubuntu | yakkety | * |
Bacula | Ubuntu | zesty | * |