CVE-2022-37705
Summary
| CVE | CVE-2022-37705 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-16 01:15:00 UTC |
| Updated | 2023-12-03 11:15:00 UTC |
| Description | A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerable component is the runtar SUID program, which is a wrapper to run /usr/bin/tar with specific arguments that are controllable by the attacker. This program mishandles the arguments passed to tar binary (it expects that the argument name and value are separated with a space; however, separating them with an equals sign is also supported), |
Risk And Classification
Problem Types: CWE-88
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Amanda Network Backup: Open Source Backup for Linux, Windows, UNIX and OS X | MISC | www.amanda.org | |
| [SECURITY] Fedora 37 Update: amanda-3.5.3-1.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 36 Update: amanda-3.5.3-1.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 36 Update: amanda-3.5.3-1.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Fixes Open Vulnerability CVE-2022-37705 by prajwaltr93 · Pull Request #196 · zmanda/amanda · GitHub | MISC | github.com | |
| MARC: Mailing list ARChives | MISC | marc.info | |
| CVE-2022-37703 - directory existence disclosure via SUID calcsize binary · Issue #192 · zmanda/amanda · GitHub | MISC | github.com | |
| Fixes Open Vulnerability CVE-2022-37705 by prajwaltr93 · Pull Request #194 · zmanda/amanda · GitHub | MISC | github.com | |
| [SECURITY] Fedora 37 Update: amanda-3.5.3-1.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [debian-lts-announce] 20231203 [SECURITY] [DLA 3681-1] amanda security update | lists.debian.org | ||
| [SECURITY] Fedora 38 Update: amanda-3.5.3-1.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 38 Update: amanda-3.5.3-1.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| GitHub - MaherAzzouzi/CVE-2022-37705: Amanda 3.5.1 second LPE. | MISC | github.com | |
| Fix to backups failing after Fix to CVE-2022-37705 runtar.c by prajwaltr93 · Pull Request #204 · zmanda/amanda · GitHub | MISC | github.com | |
| Release tag-community-3.5.3 · zmanda/amanda · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 184314 Debian Security Update for amanda (CVE-2022-37705)
- 199250 Ubuntu Security Notification for amanda Vulnerabilities (USN-5966-1)
- 283847 Fedora Security Update for amanda (FEDORA-2023-e295804b3d)
- 283848 Fedora Security Update for amanda (FEDORA-2023-1293196f34)
- 284223 Fedora Security Update for amanda (FEDORA-2023-3d0619d767)
- 6000371 Debian Security Update for amanda (DLA 3681-1)