CVE-2022-37704

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
VendorProductVersion
zmandaamanda
3.5.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
amanda
bullseye
vulnerable
bullseye (security)
1:3.5.1-7+deb11u1
fixed
bookworm
1:3.5.1-11+deb12u1
fixed
sid
1:3.5.4-1
fixed
trixie
1:3.5.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
amanda
lunar
Fixed 1:3.5.1-11
released
kinetic
Fixed 1:3.5.1-9ubuntu0.3
released
jammy
Fixed 1:3.5.1-8ubuntu1.3
released
focal
Fixed 1:3.5.1-2ubuntu0.3
released
bionic
Fixed 1:3.5.1-1ubuntu0.3
released
xenial
ignored
trusty
ignored
References