Permissions, Privileges, and Access Controls - CVE-2012-4430
Published: October 10, 2012 / Updated: August 3, 2020
Vulnerability identifier: #VU33111
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-4430
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote #AU# to gain access to sensitive information.
The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.
Affected software
Gentoo Linux
Fedora
libxslt (Alpine package)
bacula
Fedora
libxslt (Alpine package)
bacula
How to mitigate CVE-2012-4430
Install update from vendor's website.
libxslt (Alpine package) - update to 1.1.27-r0
bacula - update to 2.4.4-11.el5
bacula - update to 2.4.4-11.el5
External References
- http://secunia.com/advisories/50535
- http://secunia.com/advisories/50808
- http://sourceforge.net/projects/bacula/files/bacula/5.2.12/ReleaseNotes/view
- http://www.bacula.org/en/?page=news
- http://www.bacula.org/git/cgit.cgi/bacula/commit/?id=67debcecd3d530c429e817e1d778e79dcd1db905
- http://www.debian.org/security/2012/dsa-2558
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:166
- http://www.openwall.com/lists/oss-security/2012/09/14/11
- http://www.openwall.com/lists/oss-security/2012/09/14/12
- http://www.openwall.com/lists/oss-security/2012/09/15/2
- http://www.securityfocus.com/bid/55505