First published: Wed Jul 26 2023(Updated: )
AMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for runtar.c, a different vulnerability than CVE-2022-37705.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/amanda | <=1:3.5.1-2<=1:3.5.1-7 | 1:3.5.1-2+deb10u2 1:3.5.1-11+deb12u1 1:3.5.1-11.1 |
ubuntu/amanda | <1:3.5.1-1ubuntu0.3+ | 1:3.5.1-1ubuntu0.3+ |
ubuntu/amanda | <1:3.5.1-2ubuntu0.4 | 1:3.5.1-2ubuntu0.4 |
ubuntu/amanda | <1:3.5.1-8ubuntu1.4 | 1:3.5.1-8ubuntu1.4 |
ubuntu/amanda | <1:3.5.1-11ubuntu0.23.10.1 | 1:3.5.1-11ubuntu0.23.10.1 |
Zmanda ZRM for MySQL | <3.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30577 is rated as a medium severity vulnerability.
To fix CVE-2023-30577, upgrade to AMANDA version 3.5.4 or later.
AMANDA versions prior to 3.5.4 are affected by CVE-2023-30577.
CVE-2023-30577 can be exploited through improper argument handling in the runtar.c component.
Yes, specific fix versions for various distributions include AMANDA 1:3.5.1-2+deb10u2 for Debian and 1:3.5.1-1ubuntu0.3+ for Ubuntu Bionic.