CVE-2023-30577Improper Input Validation in Amanda

Severity
7.8HIGHNVD
OSV6.7
EPSS
0.1%
top 65.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateJan 30

Description

AMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for runtar.c, a different vulnerability than CVE-2022-37705.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDzmanda/amanda< 3.5.4
debiandebian/amanda< amanda 1:3.5.1-11+deb12u1 (bookworm)
Debianamanda/amanda< 1:3.5.1-7+deb11u1+2

🔴Vulnerability Details

1
OSV
CVE-2023-30577: AMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-32023-07-26

📋Vendor Advisories

3
Ubuntu
amanda vulnerability2024-01-30
Red Hat
amanda: Improper argument checking for runtar.c2023-06-27
Debian
CVE-2023-30577: amanda - AMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-...2023