Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconf/randpass when openssl is not available, or (2) the mtx.[PID] temporary file in mtx-changer.in.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
bacula不安全临时文件创建漏洞
Vulnerability Description
bacula是一个备份工具,可以在网络上各种不同系统之间,实现文件的备份、恢复和验证等等功能。它是基于传统的客户/服务器模式的网络备份程序,被誉为开源平台下最优秀的网络备份工具之一。功能强大的它,完全可以和商用备份软件相媲美。 bacula 1.36.3版本及早期版本中,本地用户可以对:(1) 如果没有 openssl, 对autoconf/randpass使用的临时文件,或(2)mtx-changer.in中的mtx.[PID]临时文件发起symlink攻击。
CVSS Information
N/A
Vulnerability Type
N/A