CVE-2022-37703

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
13/09/2022
Last modified:
03/12/2023

Description

In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use `opendir()` as root directly without checking the path, letting the attacker provide an arbitrary path.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:amanda:amanda:3.5.1:*:*:*:*:*:*:*