Debian Security Advisory
DLA-3330-1 amanda -- LTS security update
- Date Reported:
- 21 Feb 2023
- Affected Packages:
- amanda
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2022-37704.
- More information:
-
It was discovered that there was a potential privilege escalation vulnerability in the "amanda" backup utility.
The SUID binary located at
/lib/amanda/rundump
executed/usr/sbin/dump
as root with arguments controlled by the attacker, which may have led to an escalation of privileges, denial of service (DoS) or information disclosure.For Debian 10
Buster
, this problem has been fixed in version 1:3.5.1-2+deb10u1.We recommend that you upgrade your amanda packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS