In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in Bareos versions 19.2.8, 18.2.9 and 17.2.10.
{
"binaries": [
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-client"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-common"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-common-mysql"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-common-pgsql"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-common-sqlite3"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-console"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-console-qt"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-director-common"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-director-mysql"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-director-pgsql"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-director-sqlite3"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-fd"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-sd"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-sd-mysql"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-sd-pgsql"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-sd-sqlite3"
},
{
"binary_version": "7.0.5+dfsg-4ubuntu0.1",
"binary_name": "bacula-server"
}
]
}
{
"binaries": [
{
"binary_version": "14.2.6-3",
"binary_name": "bareos"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-bat"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-bconsole"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-client"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-common"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-database-common"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-database-mysql"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-database-postgresql"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-database-sqlite3"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-database-tools"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-devel"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-director"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-director-python-plugin"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-filedaemon"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-filedaemon-python-plugin"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-storage"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-storage-fifo"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-storage-python-plugin"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-storage-tape"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-tools"
},
{
"binary_version": "14.2.6-3",
"binary_name": "bareos-traymonitor"
}
]
}
{
"binaries": [
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-bscan"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-client"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-common"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-common-mysql"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-common-pgsql"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-common-sqlite3"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-console"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-console-qt"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-director"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-director-common"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-director-mysql"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-director-pgsql"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-director-sqlite3"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-fd"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-sd"
},
{
"binary_version": "9.0.6-1build1",
"binary_name": "bacula-server"
}
]
}
{
"binaries": [
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-bscan"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-client"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-common"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-common-mysql"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-common-pgsql"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-common-sqlite3"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-console"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-console-qt"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-director"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-director-common"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-director-mysql"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-director-pgsql"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-director-sqlite3"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-fd"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-sd"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-server"
},
{
"binary_version": "9.4.2-2ubuntu5",
"binary_name": "bacula-tray-monitor"
}
]
}