187
VMScore

CVE-2007-5626

Published: 23/10/2007 Updated: 25/01/2024
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent malicious users to obtain the password by listing the process and its arguments, or by sniffing the network.

Vulnerable Product Search on Vulmon Subscribe to Product

bacula bacula

Vendor Advisories

Debian Bug report logs - #446809 CVE-2007-5626 unauthorized disclosure of information via clear-text passwords used in command line arguments Package: bacula-director-mysql; Maintainer for bacula-director-mysql is Debian Bacula Team <pkg-bacula-devel@listsaliothdebianorg>; Source for bacula-director-mysql is src:bacula (PTS, buil ...