CVE-2020-11061
Bareos vulnerability analysis and mitigation

Overview

A heap overflow vulnerability was discovered in Bareos Director versions less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7. The vulnerability was assigned CVE-2020-11061 and was discovered on March 13, 2020, with public disclosure on July 9, 2020. The issue affects the Bareos backup software's director component (Bareos Advisory, NVD).

Technical details

The vulnerability exists in the director component where a heap overflow can occur during the initialization of a verify job. The issue stems from the code not checking if the target buffer that scanf() writes into is large enough to fit the data, specifically when processing digest strings. The vulnerability has a CVSS v3.1 base score of 7.4 (High), with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L. The issue was identified in the fd_cmds.cc file, specifically around line 1119 (Bareos Bug).

Impact

The vulnerability allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. This could potentially lead to remote control over the director from a client, resulting in unauthorized access and potential system compromise (Bareos Advisory).

Exploitability

The vulnerability can be exploited by running a Verify job with level InitCatalog against a malicious file daemon that sends arbitrary length Digests. The attack requires network access and low privileges, but no user interaction (Bareos Bug).

Mitigation and workarounds

The vulnerability was patched in Bareos versions 19.2.8, 18.2.9, and 17.2.10. The fix ensures the buffer is large enough by resizing it to the size of the message buffer being parsed. As a temporary workaround, users can disable verify jobs to mitigate the problem (Bareos Advisory).

Additional resources


SourceThis report was generated using AI

Related Bareos vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-24755CRITICAL9.8
  • Bareos logoBareos
  • cpe:2.3:a:bareos:bareos
NoYesMar 15, 2022
CVE-2024-45044HIGH8.8
  • Bareos logoBareos
  • bareos
NoYesSep 10, 2024
CVE-2022-24756HIGH7.5
  • Bareos logoBareos
  • bareos
NoYesMar 15, 2022
CVE-2020-11061HIGH7.4
  • Bareos logoBareos
  • cpe:2.3:a:bareos:bareos
NoYesJul 10, 2020
CVE-2020-4042MEDIUM6.8
  • Bareos logoBareos
  • cpe:2.3:a:bareos:bareos
NoYesJul 10, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management