CVE-2020-11061: Bareos

High severity, CVSS 7.4. EPSS: 1.2% chance of exploitation in the next 30 days.

In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in Bareos versions 19.2.8, 18.2.9 and 17.2.10.

Affected products

  • Bareos Bareos: up to and including 16.2.10; from 17.2.4, up to and including 17.2.9; from 18.2.5, up to and including 18.2.8; from 18.4.1, up to and including 19.2.7; version 18.2.4 only
  • Debian Debian Linux: version 9.0 only

Published 2020-07-10. Last modified 2026-06-17.