CVE-2016-10730

Description

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It runs binaries with root permissions when parsing the command line argument --star-path.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.096

Associated Vulnerability

VulnerabilityOS Platform
amanda Security Update (ALAS-2023-2218) amanda-3.3.9-1.amzn2.0.1.x86_64.rpmLinux
amanda Security Update (ALAS-2023-2218) amanda-libs-3.3.9-1.amzn2.0.1.x86_64.rpmLinux
amanda Security Update (ALAS-2023-2218) amanda-client-3.3.9-1.amzn2.0.1.x86_64.rpmLinux
amanda Security Update (ALAS-2023-2218) amanda-server-3.3.9-1.amzn2.0.1.x86_64.rpmLinux
amanda Security Update (ALAS2-2023-2218) amanda-3.3.9-1.amzn2.0.1.x86_64.rpmLinux
amanda Security Update (ALAS2-2023-2218) amanda-client-3.3.9-1.amzn2.0.1.x86_64.rpmLinux
amanda Security Update (ALAS2-2023-2218) amanda-libs-3.3.9-1.amzn2.0.1.x86_64.rpmLinux
amanda Security Update (ALAS2-2023-2218) amanda-server-3.3.9-1.amzn2.0.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234