In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in Bareos versions 19.2.8, 18.2.9 and 17.2.10.
{
"binaries": [
{
"binary_name": "bacula",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-client",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-common",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-common-mysql",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-common-pgsql",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-common-sqlite3",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-console",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-console-qt",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-director-common",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-director-mysql",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-director-pgsql",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-director-sqlite3",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-fd",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-sd",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-sd-mysql",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-sd-pgsql",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-sd-sqlite3",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
},
{
"binary_name": "bacula-server",
"binary_version": "7.0.5+dfsg-4ubuntu0.1"
}
]
}
{
"binaries": [
{
"binary_name": "bareos",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-bat",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-bconsole",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-client",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-common",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-database-common",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-database-mysql",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-database-postgresql",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-database-sqlite3",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-database-tools",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-devel",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-director",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-director-python-plugin",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-filedaemon",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-filedaemon-python-plugin",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-storage",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-storage-fifo",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-storage-python-plugin",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-storage-tape",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-tools",
"binary_version": "14.2.6-3"
},
{
"binary_name": "bareos-traymonitor",
"binary_version": "14.2.6-3"
}
]
}
{
"binaries": [
{
"binary_name": "bacula",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-bscan",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-client",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-common",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-common-mysql",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-common-pgsql",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-common-sqlite3",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-console",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-console-qt",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-director",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-director-common",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-director-mysql",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-director-pgsql",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-director-sqlite3",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-fd",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-sd",
"binary_version": "9.0.6-1build1"
},
{
"binary_name": "bacula-server",
"binary_version": "9.0.6-1build1"
}
]
}
{
"binaries": [
{
"binary_name": "bacula",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-bscan",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-client",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-common",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-common-mysql",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-common-pgsql",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-common-sqlite3",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-console",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-console-qt",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-director",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-director-common",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-director-mysql",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-director-pgsql",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-director-sqlite3",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-fd",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-sd",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-server",
"binary_version": "9.4.2-2ubuntu5"
},
{
"binary_name": "bacula-tray-monitor",
"binary_version": "9.4.2-2ubuntu5"
}
]
}