Amanda 3.5.1 allows privilege escalation from the regular...
Moderate severity
Unreviewed
Published
Apr 16, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Apr 16, 2023
Published to the GitHub Advisory Database
Apr 16, 2023
Last updated
Apr 4, 2024
Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.
References