Debian Package Tracker
Register | Log in
Subscribe

bareos

Backup Archiving Recovery Open Sourced - metapackage

Choose email to subscribe with

general
  • source: bareos (main)
  • version: 17.2.7-2.1
  • maintainer: Bareos Packaging Team (DMD)
  • uploaders: Dominik George [DMD]
  • arch: any
  • std-ver: 4.3.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 16.2.4-3+deb9u2
  • stable: 16.2.6-5
  • unstable: 17.2.7-2.1
versioned links
  • 16.2.4-3+deb9u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 16.2.6-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 17.2.7-2.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • bareos (2 bugs: 2, 0, 0, 0)
  • bareos-bconsole
  • bareos-client
  • bareos-common
  • bareos-database-common (4 bugs: 1, 3, 0, 0)
  • bareos-database-mysql
  • bareos-database-postgresql
  • bareos-database-sqlite3
  • bareos-database-tools
  • bareos-devel
  • bareos-director (1 bugs: 0, 1, 0, 0)
  • bareos-director-python-plugin
  • bareos-filedaemon (2 bugs: 0, 2, 0, 0)
  • bareos-filedaemon-ceph-plugin
  • bareos-filedaemon-glusterfs-plugin
  • bareos-filedaemon-ldap-python-plugin
  • bareos-filedaemon-python-plugin
  • bareos-storage (1 bugs: 0, 1, 0, 0)
  • bareos-storage-ceph
  • bareos-storage-fifo
  • bareos-storage-glusterfs
  • bareos-storage-python-plugin
  • bareos-storage-tape
  • bareos-tools
  • bareos-traymonitor (1 bugs: 0, 1, 0, 0)
action needed
Debci reports failed tests high
  • unstable: fail (log)
    The tests ran in 0:09:34
    Last run: 2021-04-14 23:35:59 UTC
    Previous status: fail

  • testing: pass (log)
    The tests ran in 0:05:14
    Last run: 2019-08-25 22:02:44 UTC
    Previous status: fail

  • stable: fail (log)
    The tests ran in 0:06:09
    Last run: 2019-06-30 21:44:18 UTC
    Previous status: fail

Created: 2019-02-11 Last update: 2021-04-22 22:03
1 binary package has unsatisfiable dependencies high
  • The dependencies of bareos-filedaemon-ldap-python-plugin=17.2.7-2.1 cannot be satisfied in unstable on mips64el, armel, armhf, amd64, i386, ppc64el, s390x, mipsel, and arm64 because: unsatisfied dependency on python-ldap
Created: 2020-03-02 Last update: 2021-04-22 22:01
A new upstream version is available: 21.0.0-pre high
A new upstream version 21.0.0-pre is available, you should consider packaging it.
Created: 2020-07-03 Last update: 2021-04-22 19:01
The VCS repository is not up to date, push the missing commits. high
vcswatch reports that the current version of the package is not in its VCS.
Either you need to push your commits and/or your tags, or the information about the package's VCS are out of date. A common cause of the latter issue when using the Git VCS is not specifying the correct branch when the packaging is not in the default one (remote HEAD branch), which is usually "master" but can be modified in salsa.debian.org in the project's general settings with the "Default Branch" field). Alternatively the Vcs-Git field in debian/control can contain a "-b <branch-name>" suffix to indicate what branch is used for the Debian packaging.
Created: 2019-12-14 Last update: 2021-04-19 05:30
3 security issues in sid high

There are 3 open security issues in sid.

3 important issues:
  • CVE-2017-14610: bareos-dir, bareos-fd, and bareos-sd in bareos-core in Bareos 16.2.6 and earlier create a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command.
  • CVE-2020-11061: In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in Bareos versions 19.2.8, 18.2.9 and 17.2.10.
  • CVE-2020-4042: Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to the director itself leading to the director responding to the replayed challenge. The response obtained is then a valid reply to the directors original challenge. This is fixed in version 19.2.8.
Created: 2021-02-19 Last update: 2021-03-21 19:04
lintian reports 2 errors and 24 warnings high
Lintian reports 2 errors and 24 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2020-07-29 Last update: 2021-01-27 03:01
AppStream hints: 1 error high
AppStream found metadata issues for packages:
  • bareos-traymonitor: 1 error
You should get rid of them to provide more metadata about this software.
Created: 2018-06-04 Last update: 2019-02-12 11:30
The package has not entered testing even though the delay is over normal
The package has not entered testing even though the 20-day delay is over. Check why.
Created: 2019-12-19 Last update: 2021-04-22 21:34
Depends on packages which need a new maintainer normal
The packages that bareos depends on which need a new maintainer are:
  • dh-exec (#851746)
    • Build-Depends: dh-exec
  • scsitools (#895273)
    • Suggests: scsitools
Created: 2019-11-22 Last update: 2021-04-22 20:07
Multiarch hinter reports 3 issue(s) normal
There are issues with the multiarch metadata for this package.
  • bareos could be marked Multi-Arch: same
  • bareos-client could be marked Multi-Arch: same
  • bareos-filedaemon-ldap-python-plugin could be marked Multi-Arch: same
Created: 2020-02-11 Last update: 2021-04-22 19:33
piuparts found (un)installation error(s) normal
Piuparts stresses package installation, uninstallation, upgrade, ... While doing such tests, one or more errors were found for the following suites:
  • sid - piuparts
You should fix them.
Created: 2021-04-05 Last update: 2021-04-05 17:01
3 low-priority security issues in buster low

There are 3 open security issues in buster.

1 issue left for the package maintainer to handle:
  • CVE-2020-11061: (needs triaging) In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in Bareos versions 19.2.8, 18.2.9 and 17.2.10.

You can find information about how to handle this issue in the security team's documentation.

2 ignored issues:
  • CVE-2017-14610: bareos-dir, bareos-fd, and bareos-sd in bareos-core in Bareos 16.2.6 and earlier create a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command.
  • CVE-2020-4042: Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to the director itself leading to the director responding to the replayed challenge. The response obtained is then a valid reply to the directors original challenge. This is fixed in version 19.2.8.
Created: 2021-02-19 Last update: 2021-03-21 19:04
Build log checks report 2 warnings low
Build log checks report 2 warnings
Created: 2020-01-14 Last update: 2020-01-14 21:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.5.1 instead of 4.3.0).
Created: 2019-07-08 Last update: 2020-11-17 05:41
testing migrations
  • excuses:
    • Migration status for bareos (- to 17.2.7-2.1): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • bareos-filedaemon-ldap-python-plugin/amd64 has unsatisfiable dependency
    • bareos-filedaemon-ldap-python-plugin/arm64 has unsatisfiable dependency
    • bareos-filedaemon-ldap-python-plugin/armel has unsatisfiable dependency
    • bareos-filedaemon-ldap-python-plugin/armhf has unsatisfiable dependency
    • bareos-filedaemon-ldap-python-plugin/i386 has unsatisfiable dependency
    • bareos-filedaemon-ldap-python-plugin/mips64el has unsatisfiable dependency
    • bareos-filedaemon-ldap-python-plugin/mipsel has unsatisfiable dependency
    • bareos-filedaemon-ldap-python-plugin/ppc64el has unsatisfiable dependency
    • bareos-filedaemon-ldap-python-plugin/s390x has unsatisfiable dependency
    • Updating bareos introduces new bugs: #922344, #936185, #965985, #968957, #977707, #977708
    • blocked by freeze: is not in testing
    • Additional info:
    • Cannot be tested by piuparts (not a blocker) - https://piuparts.debian.org/sid/source/b/bareos.html
    • uninstallable on arch amd64, not running autopkgtest there
    • uninstallable on arch arm64, not running autopkgtest there
    • uninstallable on arch armhf, not running autopkgtest there
    • uninstallable on arch i386, not running autopkgtest there
    • uninstallable on arch ppc64el, not running autopkgtest there
    • 496 days old (needed 20 days)
    • Not considered
news
[rss feed]
  • [2019-12-13] Accepted bareos 17.2.7-2.1 (source) into unstable (Jakob Haufe)
  • [2019-09-03] bareos REMOVED from testing (Debian testing watch)
  • [2019-02-23] Accepted bareos 17.2.7-2 (source amd64) into unstable (Dominik George)
  • [2019-02-11] Accepted bareos 17.2.7-1 (source amd64) into unstable (Dominik George)
  • [2019-02-09] bareos 16.2.6-5 MIGRATED to testing (Debian testing watch)
  • [2019-02-06] Accepted bareos 16.2.6-5 (source amd64) into unstable (Dominik George)
  • [2018-06-22] bareos REMOVED from testing (Debian testing watch)
  • [2018-05-18] bareos 16.2.6-4 MIGRATED to testing (Debian testing watch)
  • [2018-05-15] Accepted bareos 16.2.6-4 (source) into unstable (Felix Geyer)
  • [2018-03-02] Accepted bareos 16.2.4-3+deb9u2 (source) into proposed-updates->stable-new, proposed-updates (Felix Geyer)
  • [2017-08-23] Accepted bareos 14.2.1+20141017gitc6c5b56-3+deb8u3 (source amd64) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Felix Geyer)
  • [2017-08-23] Accepted bareos 16.2.4-3+deb9u1 (source amd64) into proposed-updates->stable-new, proposed-updates (Felix Geyer)
  • [2017-08-06] bareos 16.2.6-3 MIGRATED to testing (Debian testing watch)
  • [2017-07-30] Accepted bareos 16.2.6-3 (source) into unstable (Felix Geyer)
  • [2017-07-27] Accepted bareos 16.2.6-2 (source) into unstable (Felix Geyer)
  • [2017-07-05] bareos 16.2.6-1 MIGRATED to testing (Debian testing watch)
  • [2017-06-29] Accepted bareos 16.2.6-1 (source) into unstable (Felix Geyer)
  • [2017-06-23] bareos 16.2.5-2 MIGRATED to testing (Debian testing watch)
  • [2017-06-18] Accepted bareos 16.2.5-2 (source) into unstable (Felix Geyer)
  • [2017-04-20] Accepted bareos 16.2.5-1 (source) into experimental (Felix Geyer)
  • [2017-01-22] bareos 16.2.4-3 MIGRATED to testing (Debian testing watch)
  • [2017-01-10] Accepted bareos 16.2.4-3 (source amd64) into unstable (Felix Geyer)
  • [2016-12-03] bareos 16.2.4-2 MIGRATED to testing (Debian testing watch)
  • [2016-11-27] Accepted bareos 16.2.4-2 (source) into unstable (Felix Geyer)
  • [2016-11-06] Accepted bareos 16.2.4-1 (source) into experimental (Felix Geyer)
  • [2016-10-24] bareos 15.2.4-2 MIGRATED to testing (Debian testing watch)
  • [2016-10-16] Accepted bareos 15.2.4-2 (source) into unstable (Felix Geyer)
  • [2016-07-09] bareos 15.2.4-1 MIGRATED to testing (Debian testing watch)
  • [2016-07-03] Accepted bareos 15.2.4-1 (source) into unstable (Felix Geyer)
  • [2016-04-28] bareos 15.2.3-2 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 17
  • RC: 7
  • I&N: 9
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (2, 24)
  • buildd: logs, checks, clang, debcheck, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • l10n (-, 18)
  • debci

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing