cve/2022/CVE-2022-37704.md
2024-06-22 09:37:59 +00:00

975 B

CVE-2022-37704

Description

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.

POC

Reference

Github