Description
Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3330-1 | amanda security update |
Debian DLA |
DLA-3880-1 | amanda security update |
EUVD |
EUVD-2022-40318 | Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure. |
Ubuntu USN |
USN-5966-1 | amanda vulnerabilities |
Ubuntu USN |
USN-5966-3 | amanda regression |
References
History
Tue, 04 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 06 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-04T16:09:49.172Z
Reserved: 2022-08-08T00:00:00.000Z
Link: CVE-2022-37704
Updated: 2025-11-04T16:09:49.172Z
Status : Modified
Published: 2023-04-16T01:15:06.823
Modified: 2025-11-04T16:15:50.797
Link: CVE-2022-37704
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN