Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2022-37705 Details

Description

A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerable component is the runtar SUID program, which is a wrapper to run /usr/bin/tar with specific arguments that are controllable by the attacker. This program mishandles the arguments passed to tar binary (it expects that the argument name and value are separated with a space; however, separating them with an equals sign is also supported),

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://github.com/MaherAzzouzi/CVE-2022-37705 CVEExploitThird Party Advisory
https://github.com/zmanda/amanda/issues/192 CVE
https://github.com/zmanda/amanda/pull/194 CVEPatch
https://github.com/zmanda/amanda/pull/196 CVEPatch
https://github.com/zmanda/amanda/pull/204 CVEPatch

see all 25 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')[email protected]

Affected Products

ProductVersions
zmanda amanda
3.5.1

CPE

  • cpe:2.3:a:zmanda:amanda:3.5.1:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

11 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2022-37705
NVD Published Date:
Apr 16, 2023
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2022-37705 Details - Not Deferred