7.2
CVSSv2

CVE-2016-10730

Published: 24/10/2018 Updated: 09/01/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It runs binaries with root permissions when parsing the command line argument --star-path.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zmanda amanda 3.3.1

redhat enterprise linux 7.0

Vendor Advisories

An issue was discovered in Amanda 331 A user with backup privileges can trivially compromise a client installation The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root (CVE-2016-10729) An issue was discovered in Amanda 331 ...