CVE-2016-10729
Summary
| CVE | CVE-2016-10729 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-24 21:29:00 UTC |
| Updated | 2019-01-09 19:54:00 UTC |
| Description | An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Amanda 3.3.1 - Local Privilege Escalation - Linux local Exploit |
EXPLOIT-DB |
www.exploit-db.com |
Exploit, Third Party Advisory, VDB Entry |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 355830 Amazon Linux Security Advisory for amanda : ALAS-2023-1808
- 355841 Amazon Linux Security Advisory for amanda : ALAS2-2023-2218