CVE-2022-37704

Published
View on NVD ↗
CVSS v3
6.7
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS

Description

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.

Amanda Network Backup
GitHubGitHub
265
Amanda 3.5.1 LPE
GitHubGitHub
4