CVE-2022-37703Path Traversal in Amanda

Severity
3.3LOWNVD
EPSS
2.2%
top 15.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 13
Latest updateApr 3

Description

In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use `opendir()` as root directly without checking the path, letting the attacker provide an arbitrary path.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages4 packages

debiandebian/amanda< amanda 1:3.5.1-10 (bookworm)
Debianamanda/amanda< 1:3.5.1-7+deb11u1+2
Ubuntuamanda/amanda< 1:3.3.3-2ubuntu1.1+esm1+12
NVDamanda/amanda3.5.1

🔴Vulnerability Details

5
OSV
amanda regression2023-04-03
OSV
amanda vulnerabilities2023-03-23
OSV
amanda regression2023-03-23
GHSA
GHSA-j9rc-2hv9-v5v8: In Amanda 32022-09-14
OSV
CVE-2022-37703: In Amanda 32022-09-13

📋Vendor Advisories

5
Ubuntu
amanda regression2023-04-03
Ubuntu
amanda vulnerabilities2023-03-23
Ubuntu
amanda regression2023-03-23
Red Hat
amanda: information leak (discovery of directory existence)2022-09-13
Debian
CVE-2022-37703: amanda - In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUI...2022