AMANDA, the Advanced Maryland Automatic Network Disk Archiver, is a backup system that allows the administrator of a LAN to set up a single master backup server to back up multiple hosts to a single large capacity tape or disk drive. Amanda uses native tools (such as GNUtar, dump) for backup and can back up a large number of workstations running multiple versions of Unix/Mac OS X/Linux/Windows.
Security Fix(es):
A flaw was found in Amanda. The runtar
SUID binary executes /usr/bin/tar as root without properly validating its arguments, possibly leading to escalation of privileges from the regular user "amandabackup" to root.(CVE-2022-37705)
A flaw was found in Amanda. The rundump
SUID binary executes /usr/sbin/dump as root without properly validating its arguments, possibly leading to escalation of privileges from the regular user "amandabackup" to root.(CVE-2022-37704)
{ "severity": "Medium" }
{ "x86_64": [ "amanda-3.5.1-20.oe1.x86_64.rpm", "amanda-debugsource-3.5.1-20.oe1.x86_64.rpm", "amanda-debuginfo-3.5.1-20.oe1.x86_64.rpm" ], "src": [ "amanda-3.5.1-20.oe1.src.rpm" ], "noarch": [ "amanda-help-3.5.1-20.oe1.noarch.rpm" ], "aarch64": [ "amanda-3.5.1-20.oe1.aarch64.rpm", "amanda-debuginfo-3.5.1-20.oe1.aarch64.rpm", "amanda-debugsource-3.5.1-20.oe1.aarch64.rpm" ] }
{ "x86_64": [ "amanda-debugsource-3.5.1-20.oe1.x86_64.rpm", "amanda-debuginfo-3.5.1-20.oe1.x86_64.rpm", "amanda-3.5.1-20.oe1.x86_64.rpm" ], "src": [ "amanda-3.5.1-20.oe1.src.rpm" ], "noarch": [ "amanda-help-3.5.1-20.oe1.noarch.rpm" ], "aarch64": [ "amanda-debuginfo-3.5.1-20.oe1.aarch64.rpm", "amanda-debugsource-3.5.1-20.oe1.aarch64.rpm", "amanda-3.5.1-20.oe1.aarch64.rpm" ] }
{ "x86_64": [ "amanda-debuginfo-3.5.1-21.oe2203.x86_64.rpm", "amanda-3.5.1-21.oe2203.x86_64.rpm", "amanda-debugsource-3.5.1-21.oe2203.x86_64.rpm", "amanda-debugsource-3.5.1-23.oe2203sp1.x86_64.rpm", "amanda-3.5.1-23.oe2203sp1.x86_64.rpm", "amanda-debuginfo-3.5.1-23.oe2203sp1.x86_64.rpm" ], "src": [ "amanda-3.5.1-21.oe2203.src.rpm", "amanda-3.5.1-23.oe2203sp1.src.rpm" ], "noarch": [ "amanda-help-3.5.1-21.oe2203.noarch.rpm", "amanda-help-3.5.1-23.oe2203sp1.noarch.rpm" ], "aarch64": [ "amanda-debuginfo-3.5.1-21.oe2203.aarch64.rpm", "amanda-debugsource-3.5.1-21.oe2203.aarch64.rpm", "amanda-3.5.1-21.oe2203.aarch64.rpm", "amanda-debugsource-3.5.1-23.oe2203sp1.aarch64.rpm", "amanda-debuginfo-3.5.1-23.oe2203sp1.aarch64.rpm", "amanda-3.5.1-23.oe2203sp1.aarch64.rpm" ] }
{ "x86_64": [ "amanda-debugsource-3.5.1-23.oe2203sp1.x86_64.rpm", "amanda-3.5.1-23.oe2203sp1.x86_64.rpm", "amanda-debuginfo-3.5.1-23.oe2203sp1.x86_64.rpm" ], "src": [ "amanda-3.5.1-23.oe2203sp1.src.rpm" ], "noarch": [ "amanda-help-3.5.1-23.oe2203sp1.noarch.rpm" ], "aarch64": [ "amanda-debugsource-3.5.1-23.oe2203sp1.aarch64.rpm", "amanda-debuginfo-3.5.1-23.oe2203sp1.aarch64.rpm", "amanda-3.5.1-23.oe2203sp1.aarch64.rpm" ] }