Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-10730

Опубликовано: 24 окт. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.2
CVSS3: 7.8

Описание

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It runs binaries with root permissions when parsing the command line argument --star-path.

РелизСтатусПримечание
bionic

not-affected

1:3.5.1-1build2
cosmic

not-affected

1:3.5.1-1build2
devel

not-affected

1:3.5.1-1build2
disco

not-affected

1:3.5.1-1build2
eoan

not-affected

1:3.5.1-1build2
esm-apps/bionic

not-affected

1:3.5.1-1build2
esm-apps/focal

not-affected

1:3.5.1-1build2
esm-apps/jammy

not-affected

1:3.5.1-1build2
esm-apps/noble

not-affected

1:3.5.1-1build2
esm-apps/xenial

needed

Показывать по

EPSS

Процентиль: 27%
0.00096
Низкий

7.2 High

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 4.2
redhat
около 10 лет назад

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It runs binaries with root permissions when parsing the command line argument --star-path.

CVSS3: 7.8
nvd
больше 7 лет назад

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It runs binaries with root permissions when parsing the command line argument --star-path.

CVSS3: 7.8
debian
больше 7 лет назад

An issue was discovered in Amanda 3.3.1. A user with backup privileges ...

CVSS3: 7.8
github
больше 3 лет назад

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It runs binaries with root permissions when parsing the command line argument --star-path.

EPSS

Процентиль: 27%
0.00096
Низкий

7.2 High

CVSS2

7.8 High

CVSS3