Zmanda

Amanda

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.15%
  • Veröffentlicht 26.07.2023 17:15:10
  • Zuletzt bearbeitet 04.11.2025 17:15:36

AMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for runtar.c, a different vulnerability than CVE-2022-37705.

  • EPSS 0.11%
  • Veröffentlicht 16.04.2023 01:15:06
  • Zuletzt bearbeitet 04.11.2025 16:15:50

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, ...

Exploit
  • EPSS 3.12%
  • Veröffentlicht 16.04.2023 01:15:06
  • Zuletzt bearbeitet 04.11.2025 16:15:51

A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerable component is the runtar SUID program, which is a wrapper to run /usr/bin/tar with specific arguments that are controllable by t...

  • EPSS 0.25%
  • Veröffentlicht 01.12.2019 14:15:10
  • Zuletzt bearbeitet 21.11.2024 04:34:48

In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 24.10.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 02:44:36

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate comma...

  • EPSS 0.08%
  • Veröffentlicht 24.10.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 02:44:36

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It run...