Lucene search

K
cvelistMitreCVELIST:CVE-2022-37703
HistorySep 13, 2022 - 12:00 a.m.

CVE-2022-37703

2022-09-1300:00:00
mitre
www.cve.org
12
amanda 3.5.1
information leak
vulnerability
calcsize
suid
binary
opendir()

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

18.0%

In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use opendir() as root directly without checking the path, letting the attacker provide an arbitrary path.

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

18.0%