3.6
CVSSv2

CVE-2005-2995

Published: 20/09/2005 Updated: 09/10/2018
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

bacula 1.36.3 and previous versions allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconf/randpass when openssl is not available, or (2) the mtx.[PID] temporary file in mtx-changer.in.

Vulnerable Product Search on Vulmon Subscribe to Product

bacula bacula

Vendor Advisories

Debian Bug report logs - #509301 CVE-2008-5373: insecure temp file handling in mtx-changerAdic-Scalar-24 Package: bacula-common; Maintainer for bacula-common is Debian Bacula Team <pkg-bacula-devel@listsaliothdebianorg>; Source for bacula-common is src:bacula (PTS, buildd, popcon) Reported by: Steffen Joeris <steffen ...