CVE Vulnerabilities

CVE-2012-4430

Published: Oct 10, 2012 | Modified: Oct 09, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
2.7 LOW
AV:A/AC:L/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW

The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Bacula Bacula * 5.2.11 (excluding)
Bacula Ubuntu artful *
Bacula Ubuntu hardy *
Bacula Ubuntu lucid *
Bacula Ubuntu natty *
Bacula Ubuntu oneiric *
Bacula Ubuntu precise *
Bacula Ubuntu quantal *
Bacula Ubuntu raring *
Bacula Ubuntu saucy *
Bacula Ubuntu utopic *
Bacula Ubuntu vivid *
Bacula Ubuntu wily *
Bacula Ubuntu yakkety *
Bacula Ubuntu zesty *

References