CVE-2022-37704

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
16/04/2023
Last modified:
04/11/2025

Description

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zmanda:amanda:3.5.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools