First published: Wed Oct 24 2018(Updated: )
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It runs binaries with root permissions when parsing the command line argument --star-path.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zmanda Amanda | =3.3.1 | |
Red Hat Enterprise Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-10730 is considered to be high due to the potential for a user with backup privileges to compromise the client installation.
To fix CVE-2016-10730, it's recommended to restrict access to the Amstar script and review user privileges related to the Amanda backup system.
CVE-2016-10730 specifically affects Amanda version 3.3.1.
Yes, CVE-2016-10730 can affect Red Hat Enterprise Linux version 7.0 when running Amanda version 3.3.1.
A user with backup privileges can exploit CVE-2016-10730 to compromise the client installation.