Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-37705


A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerable component is the runtar SUID program, which is a wrapper to run /usr/bin/tar with specific arguments that are controllable by the attacker. This program mishandles the arguments passed to tar binary (it expects that the argument name and value are separated with a space; however, separating them with an equals sign is also supported),


Published

2023-04-16T01:15:06.867

Last Modified

2024-11-21T07:15:05.343

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-88

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zmanda amanda 3.5.1 Yes

References