Bacula MySQL Password Information Disclosure Vulnerability
BID:26156
Info
Bacula MySQL Password Information Disclosure Vulnerability
| Bugtraq ID: | 26156 |
| Class: | Design Error |
| CVE: |
CVE-2007-5626 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 22 2007 12:00AM |
| Updated: | May 07 2015 05:20PM |
| Credit: | Matthijs Kooijman discovered this issue. |
| Vulnerable: |
Gentoo Linux Bacula Bacula 2.4 Bacula Bacula 2.2.4 Bacula Bacula 0 |
| Not Vulnerable: | |
Discussion
Bacula MySQL Password Information Disclosure Vulnerability
Bacula is prone to an information-disclosure vulnerability because it fails to protect the MySQL director password.
Attackers can exploit this issue to gain unauthorized access to the affected database and then manipulate or delete sensitive information.
Bacula is prone to an information-disclosure vulnerability because it fails to protect the MySQL director password.
Attackers can exploit this issue to gain unauthorized access to the affected database and then manipulate or delete sensitive information.
Exploit / POC
Bacula MySQL Password Information Disclosure Vulnerability
To exploit this issue, attackers can use readily available commands or network utilities.
To exploit this issue, attackers can use readily available commands or network utilities.
Solution / Fix
Bacula MySQL Password Information Disclosure Vulnerability
Solution:
Please see the referenced advisories for information on obtaining and applying the appropriate updates.
Solution:
Please see the referenced advisories for information on obtaining and applying the appropriate updates.
References
Bacula MySQL Password Information Disclosure Vulnerability
References:
References: