CVE-2022-37704

EUVD-2022-40318
Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
Affected Products (NVD)
VendorProductVersion
zmandaamanda
3.5.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
amanda
bookworm
1:3.5.1-11+deb12u1
fixed
bullseye
vulnerable
bullseye (security)
1:3.5.1-7+deb11u1
fixed
sid
1:3.5.4-1
fixed
trixie
1:3.5.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
amanda
bionic
Fixed 1:3.5.1-1ubuntu0.3
released
focal
Fixed 1:3.5.1-2ubuntu0.3
released
jammy
Fixed 1:3.5.1-8ubuntu1.3
released
kinetic
Fixed 1:3.5.1-9ubuntu0.3
released
lunar
Fixed 1:3.5.1-11
released
trusty
ignored
xenial
ignored
References