7.2
CVSSv2

CVE-2016-10729

Published: 24/10/2018 Updated: 09/01/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zmanda amanda 3.3.1

redhat enterprise linux 7.0

debian debian linux 8.0

debian debian linux 10.0

debian debian linux 7.0

debian debian linux 9.0

Vendor Advisories

An issue was discovered in Amanda 331 A user with backup privileges can trivially compromise a client installation The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root (CVE-2016-10729) An issue was discovered in Amanda 331 ...
An issue was discovered in Amanda 331 A user with backup privileges can trivially compromise a client installation The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root (CVE-2016-10729) AMANDA (Advanced Maryland Automatic Netw ...