Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-37704


Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.


Published

2023-04-16T01:15:06.823

Last Modified

2025-02-06T18:15:29.863

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-77
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zmanda amanda 3.5.1 Yes

References