CVE Vulnerabilities

CVE-2016-10730

Published: Oct 24, 2018 | Modified: Jan 09, 2019
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
4.2 LOW
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It runs binaries with root permissions when parsing the command line argument –star-path.

Affected Software

Name Vendor Start Version End Version
Amanda Zmanda 3.3.1 (including) 3.3.1 (including)
Amanda Ubuntu esm-apps/xenial *
Amanda Ubuntu trusty *
Amanda Ubuntu upstream *
Amanda Ubuntu xenial *

References