CVE-2022-37705: Medium severity zmanda zrm for mysql vulnerability
A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerable component is the runtar SUID program, which is a wrapper to run /usr/bin/tar with specific arguments that are controllable by the attacker. This program mishandles the arguments passed to tar binary (it expects that the argument name and value are separated with a space; however, separating them with an equals sign is also supported),
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-37705?
CVE-2022-37705 is classified as a privilege escalation vulnerability.
How do I fix CVE-2022-37705?
To fix CVE-2022-37705, update Amanda to version 3.5.2 or later.
Who is affected by CVE-2022-37705?
CVE-2022-37705 affects users of Amanda version 3.5.1.
What component is vulnerable in CVE-2022-37705?
The runtar SUID program is the vulnerable component in CVE-2022-37705.
What can an attacker achieve with CVE-2022-37705?
An attacker exploiting CVE-2022-37705 can acquire root privileges on the affected system.