CVE-2016-10729
HIGHAmanda 3.3.1 - Authenticated Command Injection via runtar Binary Argument Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-10729. PoCs published by Hacker Fantastic.
AI-analyzed exploit summary The exploit leverages a command injection vulnerability in the setuid root binary 'runtar' in Amanda 3.3.1. By passing additional arguments after '--create', an attacker with backup privileges can execute arbitrary commands as root.
Description
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root.
Exploits (1)
The exploit leverages a command injection vulnerability in the setuid root binary 'runtar' in Amanda 3.3.1. By passing additional arguments after '--create', an attacker with backup privileges can execute arbitrary commands as root.
References (1)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H