CVE-2016-10730: High severity zmanda zrm for mysql vulnerability
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It runs binaries with root permissions when parsing the command line argument --star-path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10730?
The severity of CVE-2016-10730 is considered to be high due to the potential for a user with backup privileges to compromise the client installation.
How do I fix CVE-2016-10730?
To fix CVE-2016-10730, it's recommended to restrict access to the Amstar script and review user privileges related to the Amanda backup system.
What versions of Amanda are affected by CVE-2016-10730?
CVE-2016-10730 specifically affects Amanda version 3.3.1.
Can CVE-2016-10730 affect Red Hat Enterprise Linux?
Yes, CVE-2016-10730 can affect Red Hat Enterprise Linux version 7.0 when running Amanda version 3.3.1.
Who can exploit CVE-2016-10730?
A user with backup privileges can exploit CVE-2016-10730 to compromise the client installation.