4
CVSSv2

CVE-2012-4430

Published: 10/10/2012 Updated: 09/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The dump_resource function in dird/dird_conf.c in Bacula prior to 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bacula bacula

debian debian linux 7.0

debian debian linux 6.0

Vendor Advisories

Debian Bug report logs - #687923 bacula: CVE-2012-4430 Package: bacula; Maintainer for bacula is Debian Bacula Team <pkg-bacula-devel@listsaliothdebianorg>; Source for bacula is src:bacula (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 17 Sep 2012 07:45:01 UTC Severity: grave Ta ...
It was discovered that bacula, a network backup service, does not properly enforce console ACLs This could allow information about resources to be dumped by an otherwise-restricted client For the stable distribution (squeeze), this problem has been fixed in version 502-22+squeeze1 For the testing distribution (wheezy), this problem will be fi ...