VDB
CVE-2007-5626
CVE-2007-5626
PUBLISHED
CVSS 5.5 MEDIUM
make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the password by listing the process and its arguments, or by sniffing the network.
EPSS 0.04% · 11.1th percentile
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.04%
11.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| bacula | bacula | 0 |
Timeline
- Oct 23, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- bacula-makecatalogbackup-info-disclosure(37336) vdb
- GLSA-200807-10 vendor-advisory
- http://bugs.bacula.org/view.php?id=990 url
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=446809 url
- ADV-2007-3572 vdb
- 27243 third-party-advisory
- 41861 vdb
- 26156 vdb
- 31184 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2007-5626 advisory