Lucene search

K
nvd[email protected]NVD:CVE-2022-37704
HistoryApr 16, 2023 - 1:15 a.m.

CVE-2022-37704

2023-04-1601:15:06
CWE-77
web.nvd.nist.gov
6
amanda 3.5.1
privilege escalation
suid vulnerability
denial of service
information disclosure
root privilege

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

14.6%

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.

Affected configurations

Nvd
Node
zmandaamandaMatch3.5.1
VendorProductVersionCPE
zmandaamanda3.5.1cpe:2.3:a:zmanda:amanda:3.5.1:*:*:*:*:*:*:*

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

14.6%