Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in amanda.
Software Description:
- amanda: Advanced Maryland Automatic Network Disk Archiver (Client)
Details:
USN-5966-1 fixed vulnerabilities in amanda. Unfortunately that update
caused a regression and was reverted in USN-5966-2. This update provides
security fixes for Ubuntu 22.10, Ubuntu 22.04 LTS, Ubuntu 20.04
LTS and Ubuntu 18.04 LTS.
We apologize for the inconvenience.
Original advisory details:
Maher Azzouzi discovered an information disclosure vulnerability in the
calcsize binary within amanda. calcsize is a suid binary owned by root that
could possibly be used by a malicious local attacker to expose sensitive
file system information. (CVE-2022-37703)
Maher Azzouzi discovered a privilege escalation vulnerability in the
rundump binary within amanda. rundump is a suid binary owned by root that
did not perform adequate sanitization of environment variables or
commandline options and could possibly be used by ...
The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: amanda-client 1:3.5.1-9ubuntu0.3 Ubuntu 22.04 LTS: amanda-client 1:3.5.1-8ubuntu1.3 Ubuntu 20.04 LTS: amanda-client 1:3.5.1-2ubuntu0.3 Ubuntu 18.04 LTS: amanda-client 1:3.5.1-1ubuntu0.3 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-5966-3
https://ubuntu.com/security/notices/USN-5966-1
https://bugs.launchpad.net/ubuntu/+source/amanda/+bug/2012536
CVE-2022-37703, CVE-2022-37704, CVE-2022-37705
Get the latest Linux and open source security news straight to your inbox.