DSA-2558-1 bacula -- information disclosure

Related Vulnerabilities: CVE-2012-4430  

It was discovered that bacula, a network backup service, does not properly enforce console ACLs. This could allow information about resources to be dumped by an otherwise-restricted client. For the stable distribution (squeeze), this problem has been fixed in version 5.0.2-2.2+squeeze1. For the testing distribution (wheezy), this problem will be fixed soon. For the unstable distribution (sid), this problem has been fixed in version 5.2.6+dfsg-4. We recommend that you upgrade your bacula packages.

Debian Security Advisory

DSA-2558-1 bacula -- information disclosure

Date Reported:
08 Oct 2012
Affected Packages:
bacula
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2012-4430.
More information:

It was discovered that bacula, a network backup service, does not properly enforce console ACLs. This could allow information about resources to be dumped by an otherwise-restricted client.

For the stable distribution (squeeze), this problem has been fixed in version 5.0.2-2.2+squeeze1.

For the testing distribution (wheezy), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in version 5.2.6+dfsg-4.

We recommend that you upgrade your bacula packages.