{"id":"UBUNTU-CVE-2022-37704","details":"Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.","modified":"2026-01-30T01:10:23.995965Z","published":"2023-01-30T00:00:00Z","related":["USN-5966-3"],"upstream":["CVE-2022-37704"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-37704"},{"type":"REPORT","url":"https://github.com/MaherAzzouzi/CVE-2022-37704"},{"type":"REPORT","url":"https://github.com/zmanda/amanda/issues/192"},{"type":"REPORT","url":"https://marc.info/?l=amanda-hackers&m=167437716918603&w=2"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5966-3"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-37704"}],"affected":[{"package":{"name":"amanda","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/amanda@1:3.3.6-4.1ubuntu0.1+esm2?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:3.3.6-4","1:3.3.6-4.1","1:3.3.6-4.1ubuntu0.1","1:3.3.6-4.1ubuntu0.1+actuallyesm2","1:3.3.6-4.1ubuntu0.1+esm1","1:3.3.6-4.1ubuntu0.1+esm2"],"ecosystem_specific":{"binaries":[{"binary_name":"amanda-client","binary_version":"1:3.3.6-4.1ubuntu0.1+esm2"},{"binary_name":"amanda-common","binary_version":"1:3.3.6-4.1ubuntu0.1+esm2"},{"binary_name":"amanda-server","binary_version":"1:3.3.6-4.1ubuntu0.1+esm2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37704.json"}},{"package":{"name":"amanda","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/amanda@1:3.5.1-1ubuntu0.3?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:3.5.1-1ubuntu0.3"}]}],"versions":["1:3.3.9-5build1","1:3.5-2","1:3.5.1-1","1:3.5.1-1build1","1:3.5.1-1build2","1:3.5.1-1ubuntu0.1","1:3.5.1-1ubuntu0.2"],"ecosystem_specific":{"binaries":[{"binary_name":"amanda-client","binary_version":"1:3.5.1-1ubuntu0.3"},{"binary_name":"amanda-common","binary_version":"1:3.5.1-1ubuntu0.3"},{"binary_name":"amanda-server","binary_version":"1:3.5.1-1ubuntu0.3"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37704.json"}},{"package":{"name":"amanda","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/amanda@1:3.5.1-2ubuntu0.3?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:3.5.1-2ubuntu0.3"}]}],"versions":["1:3.5.1-2build2","1:3.5.1-2build3","1:3.5.1-2ubuntu0.1","1:3.5.1-2ubuntu0.2"],"ecosystem_specific":{"binaries":[{"binary_name":"amanda-client","binary_version":"1:3.5.1-2ubuntu0.3"},{"binary_name":"amanda-common","binary_version":"1:3.5.1-2ubuntu0.3"},{"binary_name":"amanda-server","binary_version":"1:3.5.1-2ubuntu0.3"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37704.json"}},{"package":{"name":"amanda","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/amanda@1:3.5.1-8ubuntu1.3?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:3.5.1-8ubuntu1.3"}]}],"versions":["1:3.5.1-5ubuntu1","1:3.5.1-8","1:3.5.1-8ubuntu1","1:3.5.1-8ubuntu1.1","1:3.5.1-8ubuntu1.2"],"ecosystem_specific":{"binaries":[{"binary_name":"amanda-client","binary_version":"1:3.5.1-8ubuntu1.3"},{"binary_name":"amanda-common","binary_version":"1:3.5.1-8ubuntu1.3"},{"binary_name":"amanda-server","binary_version":"1:3.5.1-8ubuntu1.3"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37704.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}