Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-5626

Опубликовано: 23 окт. 2007
Источник: debian
EPSS Низкий

Описание

make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the password by listing the process and its arguments, or by sniffing the network.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
baculafixed5.0.0-1package

Примечания

  • this script needs the default database password and name needs to be set which

  • would be a bigger problem in a non-trusted environment. Apart from

  • this is documented in the bacula documentation

  • Since bacula 5.0.0 "make_catalog_backup.pl" is used by default, which is not affected

EPSS

Процентиль: 8%
0.00034
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 18 лет назад

make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the password by listing the process and its arguments, or by sniffing the network.

CVSS3: 5.5
nvd
почти 18 лет назад

make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the password by listing the process and its arguments, or by sniffing the network.

CVSS3: 5.5
github
больше 3 лет назад

make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the password by listing the process and its arguments, or by sniffing the network.

EPSS

Процентиль: 8%
0.00034
Низкий