Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 22.10: 5966-1 Critical: Amanda Privilege Escalation Details

ubuntu
Calendar Grey March 23, 2023
Scroller Ubuntu
Several Ubuntu versions faced weaknesses in the amanda system, prompting decisive measures for improved protection.
Several security issues were fixed in amanda.

Summary

Several security issues were fixed in amanda.

Software Description:

- amanda: Advanced Maryland Automatic Network Disk Archiver (Client)

Details:

Maher Azzouzi discovered an information disclosure vulnerability in the

calcsize binary within amanda. calcsize is a suid binary owned by root that

could possibly be used by a malicious local attacker to expose sensitive

file system information. (CVE-2022-37703)

Maher Azzouzi discovered a privilege escalation vulnerability in the

rundump binary within amanda. rundump is a suid binary owned by root that

did not perform adequate sanitization of environment variables or

commandline options and could possibly be used by a malicious local

attacker to escalate privileges. (CVE-2022-37704)

Maher Azzouzi discovered a privilege escalation vulnerability in the runtar

binary within amanda. runtar is a suid binary owned by root that did not

perform adequate sanitization of commandline options and could possibly be

used by a...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
amanda-client 1:3.5.1-9ubuntu0.1

Ubuntu 22.04 LTS:
amanda-client 1:3.5.1-8ubuntu1.1

Ubuntu 20.04 LTS:
amanda-client 1:3.5.1-2ubuntu0.1

Ubuntu 18.04 LTS:
amanda-client 1:3.5.1-1ubuntu0.1

Ubuntu 16.04 ESM:
amanda-client 1:3.3.6-4.1ubuntu0.1

Ubuntu 14.04 ESM:
amanda-client 1:3.3.3-2ubuntu1.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5966-1

CVE-2022-37703, CVE-2022-37704, CVE-2022-37705

Severity
critical
Lowest
Low
Medium
High
Critical

March 23, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.