CVE-2022-37705
MEDIUMAmanda 3.5.1 - Privilege Escalation via runtar SUID Argument Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-37705. PoCs published by MaherAzzouzi.
AI-analyzed exploit summary The repository contains a functional exploit for CVE-2022-37705, demonstrating a privilege escalation flaw in Amanda 3.5.1's runtar SUID binary. The exploit leverages flawed argument checking to execute arbitrary commands as root via the --checkpoint-action parameter.
Description
A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerable component is the runtar SUID program, which is a wrapper to run /usr/bin/tar with specific arguments that are controllable by the attacker. This program mishandles the arguments passed to tar binary (it expects that the argument name and value are separated with a space; however, separating them with an equals sign is also supported),
Exploits (1)
The repository contains a functional exploit for CVE-2022-37705, demonstrating a privilege escalation flaw in Amanda 3.5.1's runtar SUID binary. The exploit leverages flawed argument checking to execute arbitrary commands as root via the --checkpoint-action parameter.
References (13)
Scores
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H