An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade amanda-debuginfoUpgrade amanda-libsUpgrade amanda-serverUpgrade amandaUpgrade amanda-client | Aug 24, 2023 | Oct 24, 2018 |
| Amazon_linux | — | Upgrade amanda | Aug 23, 2023 | Oct 24, 2018 |
| Debian | — | Upgrade amanda | Jul 30, 2024 | Oct 24, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 24, 2018 |
| Suse | — | Upgrade amanda | Nov 17, 2018 | Oct 24, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Oct 24, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub