Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Ubuntu 22.10 USN-5966-3 Moderate: Amanda Security Updates

ubuntu
Calendar Grey April 3, 2023
Scroller Ubuntu
Numerous patches have been applied to amanda across different Ubuntu iterations resolving critical vulnerabilities detected within the application.
Several security issues were fixed in amanda.

Summary

Several security issues were fixed in amanda.

Software Description:

- amanda: Advanced Maryland Automatic Network Disk Archiver (Client)

Details:

USN-5966-1 fixed vulnerabilities in amanda. Unfortunately that update

caused a regression and was reverted in USN-5966-2. This update provides

security fixes for Ubuntu 22.10, Ubuntu 22.04 LTS, Ubuntu 20.04

LTS and Ubuntu 18.04 LTS.

We apologize for the inconvenience.

Original advisory details:

Maher Azzouzi discovered an information disclosure vulnerability in the

calcsize binary within amanda. calcsize is a suid binary owned by root that

could possibly be used by a malicious local attacker to expose sensitive

file system information. (CVE-2022-37703)

Maher Azzouzi discovered a privilege escalation vulnerability in the

rundump binary within amanda. rundump is a suid binary owned by root that

did not perform adequate sanitization of environment variables or

commandline options and could possibly be used by ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
amanda-client 1:3.5.1-9ubuntu0.3

Ubuntu 22.04 LTS:
amanda-client 1:3.5.1-8ubuntu1.3

Ubuntu 20.04 LTS:
amanda-client 1:3.5.1-2ubuntu0.3

Ubuntu 18.04 LTS:
amanda-client 1:3.5.1-1ubuntu0.3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5966-3

https://ubuntu.com/security/notices/USN-5966-1

https://bugs.launchpad.net/ubuntu/+source/amanda/+bug/2012536

CVE-2022-37703, CVE-2022-37704, CVE-2022-37705

Severity
important
Lowest
Low
Medium
High
Critical

April 03, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.