VDB
CVE-2012-4430
CVE-2012-4430
PUBLISHED
CVSS 4 MEDIUM
The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.
EPSS 0.61% · 70.1th percentile
Risk Scores
CVSS 2.0
4
EPSS Score
0.61%
70.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| debian | debian_linux | 7.0, 6.0 |
| bacula | bacula | 0 |
| n/a | n/a | n/a |
Timeline
- Oct 10, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://sourceforge.net/projects/bacula/files/bacula/5.2.12/ReleaseNotes/view url
- DSA-2558 vendor-advisory
- [oss-security] 20120914 Re: Re: CVE request: bacula: Console ACL Bypass mailing-list
- MDVSA-2012:166 vendor-advisory
- http://www.bacula.org/en/?page=news url
- 55505 vdb
- 50535 third-party-advisory
- http://www.bacula.org/git/cgit.cgi/bacula/commit/?id=67debcecd3d530c429e817e1d778e79dcd1db905 url
- 50808 third-party-advisory
- [oss-security] 20120914 Re: CVE request: bacula: Console ACL Bypass mailing-list
- [oss-security] 20120914 CVE request: bacula: Console ACL Bypass mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2012-4430 advisory