CVE-2020-11061 - CVE House
Back to Database
Status published Medium CVE-2020-11061

Heap-based Buffer Overflow in Bareos Director

Vulnerability Description

In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in Bareos versions 19.2.8, 18.2.9 and 17.2.10.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-11061

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Bareos GmbH & Co. KG

View all reports →

Affected Software

Bareos Director
Vulnerable Versions:
<= 16.2.10, <= 17.2.9, <= 18.2.8, <= 19.2.7

Timeline

Official Publish: July 10th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L

Weaknesses (CWE)