Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-37704

Опубликовано: 16 апр. 2023
Источник: debian
EPSS Низкий

Описание

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
amandafixed1:3.5.1-10package

Примечания

  • https://github.com/MaherAzzouzi/CVE-2022-37704

  • https://github.com/zmanda/amanda/issues/192

  • https://marc.info/?l=amanda-hackers&m=167437716918603&w=2

  • https://github.com/zmanda/amanda/pull/197

  • https://github.com/zmanda/amanda/commit/e890d08e16ea0621966a7ae35cce53ccb44a472e

  • Followup: https://github.com/zmanda/amanda/pull/202

  • Followup: https://github.com/zmanda/amanda/pull/205

EPSS

Процентиль: 26%
0.00089
Низкий

Связанные уязвимости

CVSS3: 6.7
ubuntu
больше 2 лет назад

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.

CVSS3: 6.7
redhat
больше 2 лет назад

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.

CVSS3: 6.7
nvd
больше 2 лет назад

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.

CVSS3: 7.8
github
больше 2 лет назад

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.

suse-cvrf
больше 2 лет назад

Security update for amanda

EPSS

Процентиль: 26%
0.00089
Низкий