vendor:
Amanda
by:
Hacker Fantastic
7,2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Amanda
Affected Version From: 3.3.1
Affected Version To: 3.3.1
Patch Exists: NO
Related CWE: N/A
CPE: a:zmanda:amanda:3.3.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2013
Amanda Privilege Escalation Vulnerability
A user with backup privs can trivially compromise a client installation of Amanda. Amstar is an Amanda Application API script which should not be run by users directly. It uses star to backup and restore data and runs binaries with root permissions when parsing the command line arguement --star-path. An example is shown below where a user with backup privs can gain root access.
Mitigation:
Restrict access to the amstar binary and ensure that users with backup privs do not have access to it.