[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252271

 
 

909

 
 

196835

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2023-2218 --- amanda

ID: oval:org.secpod.oval:def:1701567Date: (C)2023-09-01   (M)2024-04-02
Class: PATCHFamily: unix




An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root. An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It runs binaries with root permissions when parsing the command line argument --star-path. AMANDA before tag-community-3.5.4 mishandles argument checking for runtar.c, a different vulnerability than CVE-2022-37705

Platform:
Amazon Linux 2
Product:
amanda
Reference:
ALAS2-2023-2218
CVE-2016-10729
CVE-2016-10730
CVE-2023-30577
CVE    3
CVE-2016-10730
CVE-2016-10729
CVE-2023-30577

© SecPod Technologies