NA

CVE-2022-37703

Published: 13/09/2022 Updated: 03/12/2023
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use `opendir()` as root directly without checking the path, letting the attacker provide an arbitrary path.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

amanda amanda 3.5.1

Vendor Advisories

Debian Bug report logs - #1021017 amanda: CVE-2022-37703 Package: src:amanda; Maintainer for src:amanda is Jose M Calhariz <calhariz@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 30 Sep 2022 14:51:06 UTC Severity: important Tags: security, upstream Reply or subscribe to this bug Togg ...
In Amanda 351, an information leak vulnerability was found in the calcsize SUID binary An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs The binary will use `opendir()` as root directly without checking the path, letting the attacker provide an arbitrary path ...