Lucene search

K
cveMitreCVE-2022-37703
HistorySep 13, 2022 - 8:15 p.m.

CVE-2022-37703

2022-09-1320:15:09
CWE-22
mitre
web.nvd.nist.gov
54
4
amanda
calcsize
suid
binary
vulnerability
directory
existence
nvd
cve-2022-37703

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

18.0%

In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use opendir() as root directly without checking the path, letting the attacker provide an arbitrary path.

Affected configurations

Nvd
Node
amandaamandaMatch3.5.1
VendorProductVersionCPE
amandaamanda3.5.1cpe:2.3:a:amanda:amanda:3.5.1:*:*:*:*:*:*:*

Social References

More

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

18.0%