Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-37703

Опубликовано: 13 сент. 2022
Источник: ubuntu
Приоритет: low
CVSS3: 3.3

Описание

In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use opendir() as root directly without checking the path, letting the attacker provide an arbitrary path.

РелизСтатусПримечание
bionic

released

1:3.5.1-1ubuntu0.3
devel

released

1:3.5.1-11
esm-apps/bionic

released

1:3.5.1-1ubuntu0.3
esm-apps/focal

released

1:3.5.1-2ubuntu0.3
esm-apps/jammy

released

1:3.5.1-8ubuntu1.3
esm-apps/xenial

ignored

regressions likely
focal

released

1:3.5.1-2ubuntu0.3
jammy

released

1:3.5.1-8ubuntu1.3
kinetic

released

1:3.5.1-9ubuntu0.3
lunar

released

1:3.5.1-11

Показывать по

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 2.3
redhat
больше 3 лет назад

In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use `opendir()` as root directly without checking the path, letting the attacker provide an arbitrary path.

CVSS3: 3.3
nvd
больше 3 лет назад

In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use `opendir()` as root directly without checking the path, letting the attacker provide an arbitrary path.

CVSS3: 3.3
debian
больше 3 лет назад

In Amanda 3.5.1, an information leak vulnerability was found in the ca ...

CVSS3: 3.3
github
больше 3 лет назад

In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use `opendir()` as root directly without checking the path, letting the attacker provide an arbitrary path.

3.3 Low

CVSS3