CVE-2022-37704
Summary
| CVE | CVE-2022-37704 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-16 01:15:00 UTC |
| Updated | 2023-11-07 03:49:00 UTC |
| Description | Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Amanda Network Backup: Open Source Backup for Linux, Windows, UNIX and OS X | MISC | www.amanda.org | |
| Update the fix for CVE-2022-37704 by pcahyna · Pull Request #205 · zmanda/amanda · GitHub | MISC | github.com | |
| [SECURITY] Fedora 37 Update: amanda-3.5.3-1.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 36 Update: amanda-3.5.3-1.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 36 Update: amanda-3.5.3-1.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| MARC: Mailing list ARChives | MISC | marc.info | |
| CVE-2022-37703 - directory existence disclosure via SUID calcsize binary · Issue #192 · zmanda/amanda · GitHub | MISC | github.com | |
| [SECURITY] Fedora 37 Update: amanda-3.5.3-1.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| GitHub - MaherAzzouzi/CVE-2022-37704: Amanda 3.5.1 LPE | MISC | github.com | |
| [SECURITY] [DLA 3330-1] amanda security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 38 Update: amanda-3.5.3-1.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 38 Update: amanda-3.5.3-1.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| CVE-2022-37704 - privilege escalation form amandabackup user to root -fix by seetharaman-rajagopal · Pull Request #197 · zmanda/amanda · GitHub | MISC | github.com | |
| Release tag-community-3.5.3 · zmanda/amanda · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181598 Debian Security Update for amanda (DLA 3330-1)
- 181895 Debian Security Update for amanda (CVE-2022-37704)
- 199250 Ubuntu Security Notification for amanda Vulnerabilities (USN-5966-1)
- 283847 Fedora Security Update for amanda (FEDORA-2023-e295804b3d)
- 283848 Fedora Security Update for amanda (FEDORA-2023-1293196f34)
- 284223 Fedora Security Update for amanda (FEDORA-2023-3d0619d767)