CVE-2005-2995

Publication date 20 September 2005

Last updated 24 July 2024


Ubuntu priority

bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconf/randpass when openssl is not available, or (2) the mtx.[PID] temporary file in mtx-changer.in.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
bacula 9.10 karmic
Fixed 1.38.9-1
9.04 jaunty
Fixed 1.38.9-1
8.10 intrepid
Fixed 1.38.9-1
8.04 LTS hardy
Fixed 1.38.9-1
7.10 gutsy
Fixed 1.38.9-1
7.04 feisty
Fixed 1.38.9-1
6.10 edgy
Fixed 1.38.9-1
6.06 LTS dapper Ignored end of life