Permissions, Privileges, and Access Controls - CVE-2012-4430

 

Permissions, Privileges, and Access Controls - CVE-2012-4430

Published: October 10, 2012 / Updated: August 3, 2020


Vulnerability identifier: #VU33111
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-4430
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to gain access to sensitive information.

The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.


Affected software

Gentoo Linux
Fedora
libxslt (Alpine package)
bacula

How to mitigate CVE-2012-4430

Install update from vendor's website.

libxslt (Alpine package) - update to 1.1.27-r0
bacula - update to 2.4.4-11.el5

External References

Related Security Bulletins