MaherAzzouzi/CVE-2022-37704

MaherAzzouzi/CVE-2022-37704

Releases0
Stars4
Amanda 3.5.1 LPE

CVE History

CVEPublishedCVSS v3CVSS v2
6.7 MEDIUM

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.