CVE-2022-37705
Ubuntu Security Notice USN-5966-2
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerable component is the runtar SUID program, which is a wrapper to run /usr/bin/tar with specific arguments that are controllable by the attacker. This program mishandles the arguments passed to tar binary (it expects that the argument name and value are separated with a space; however, separating them with an equals sign is also supported),
Maher Azzouzi discovered an information disclosure vulnerability in the calcsize binary within amanda. calcsize is a suid binary owned by root that could possibly be used by a malicious local attacker to expose sensitive file system information. Maher Azzouzi discovered a privilege escalation vulnerability in the rundump binary within amanda. rundump is a suid binary owned by root that did not perform adequate sanitization of environment variables or commandline options and could possibly be used by a malicious local attacker to escalate privileges.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2022-08-08 CVE Reserved
- 2023-03-23 CVE Published
- 2024-11-27 CVE Updated
- 2024-11-27 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CAPEC
References (12)
URL | Date | SRC |
---|---|---|
https://github.com/MaherAzzouzi/CVE-2022-37705 | 2024-11-27 |
URL | Date | SRC |
---|---|---|
https://github.com/zmanda/amanda/pull/194 | 2023-12-03 | |
https://github.com/zmanda/amanda/pull/196 | 2023-12-03 | |
https://github.com/zmanda/amanda/pull/204 | 2023-12-03 |