CVE-2023-30577
- EPSS 0.15%
- Veröffentlicht 26.07.2023 17:15:10
- Zuletzt bearbeitet 04.11.2025 17:15:36
AMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for runtar.c, a different vulnerability than CVE-2022-37705.
CVE-2022-37704
- EPSS 0.11%
- Veröffentlicht 16.04.2023 01:15:06
- Zuletzt bearbeitet 04.11.2025 16:15:50
Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, ...
CVE-2022-37705
- EPSS 3.12%
- Veröffentlicht 16.04.2023 01:15:06
- Zuletzt bearbeitet 04.11.2025 16:15:51
A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerable component is the runtar SUID program, which is a wrapper to run /usr/bin/tar with specific arguments that are controllable by t...
CVE-2019-19469
- EPSS 0.25%
- Veröffentlicht 01.12.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:48
In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials.
CVE-2016-10729
- EPSS 0.21%
- Veröffentlicht 24.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 02:44:36
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate comma...
CVE-2016-10730
- EPSS 0.08%
- Veröffentlicht 24.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 02:44:36
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It run...