AMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for runtar.c, a different vulnerability than CVE-2022-37705.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade amanda-serverUpgrade amandaUpgrade amanda-debuginfoUpgrade amanda-clientUpgrade amanda-libs | Aug 24, 2023 | Jul 26, 2023 |
| Amazon_linux | — | Upgrade amanda | Aug 23, 2023 | Jul 26, 2023 |
| Debian | — | Upgrade amanda | Dec 11, 2023 | Jul 26, 2023 |
| Huawei Euleros 2_0_sp8 | — | Upgrade amanda-clientUpgrade amandaUpgrade amanda-libsUpgrade amanda-server | Jan 10, 2024 | Jul 26, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 26, 2023 |
| Suse | — | suse-upgrade-amanda | Aug 8, 2023 | Jul 26, 2023 |
| Ubuntu | — | Upgrade amanda-client (Ubuntu Pro)Upgrade amanda-client | Jan 31, 2024 | Jul 26, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub