In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in Bareos versions 19.2.8, 18.2.9 and 17.2.10.
{ "binaries": [ { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-client" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-common" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-common-mysql" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-common-pgsql" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-common-sqlite3" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-console" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-console-qt" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-director-common" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-director-mysql" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-director-pgsql" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-director-sqlite3" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-fd" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-sd" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-sd-mysql" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-sd-pgsql" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-sd-sqlite3" }, { "binary_version": "7.0.5+dfsg-4ubuntu0.1", "binary_name": "bacula-server" } ] }
{ "binaries": [ { "binary_version": "14.2.6-3", "binary_name": "bareos" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-bat" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-bconsole" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-client" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-common" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-database-common" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-database-mysql" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-database-postgresql" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-database-sqlite3" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-database-tools" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-devel" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-director" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-director-python-plugin" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-filedaemon" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-filedaemon-python-plugin" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-storage" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-storage-fifo" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-storage-python-plugin" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-storage-tape" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-tools" }, { "binary_version": "14.2.6-3", "binary_name": "bareos-traymonitor" } ] }
{ "binaries": [ { "binary_version": "9.0.6-1build1", "binary_name": "bacula" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-bscan" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-client" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-common" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-common-mysql" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-common-pgsql" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-common-sqlite3" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-console" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-console-qt" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-director" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-director-common" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-director-mysql" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-director-pgsql" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-director-sqlite3" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-fd" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-sd" }, { "binary_version": "9.0.6-1build1", "binary_name": "bacula-server" } ] }
{ "binaries": [ { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-bscan" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-client" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-common" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-common-mysql" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-common-pgsql" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-common-sqlite3" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-console" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-console-qt" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-director" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-director-common" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-director-mysql" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-director-pgsql" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-director-sqlite3" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-fd" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-sd" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-server" }, { "binary_version": "9.4.2-2ubuntu5", "binary_name": "bacula-tray-monitor" } ] }