Lucene search

K
cvelistMitreCVELIST:CVE-2022-37704
HistoryApr 16, 2023 - 12:00 a.m.

CVE-2022-37704

2023-04-1600:00:00
mitre
www.cve.org
5
amanda
privilege escalation
suid binary
denial of service
information disclosure

AI Score

6.9

Confidence

High

EPSS

0

Percentile

14.6%

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.

AI Score

6.9

Confidence

High

EPSS

0

Percentile

14.6%