Bug 1208032 (CVE-2022-37705) - VUL-0: CVE-2022-37705: amanda: crafted arguments to the runtar SUID binary leads to local privilege escalation to root
Summary: VUL-0: CVE-2022-37705: amanda: crafted arguments to the runtar SUID binary le...
Status: RESOLVED FIXED
Alias: CVE-2022-37705
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/356357/
Whiteboard: CVSSv3.1:SUSE:CVE-2022-37705:7.8:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-02-08 08:34 UTC by Thomas Leroy
Modified: 2024-05-03 13:57 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2023-02-08 08:34:41 UTC
CVE-2022-37705

A privilege escalation flaw was found on Amanda 3.5.1 that can take backup user to root privileges. The vulnerable component is the runtar SUID that is just a wrapper to run /usr/bin/tar with specific arguments that are controllable by the attacker. The program does not check correctly the args passed to tar binary (it assumes that all args should be like this --ARG VALUE but we can provide this --ARG=VALUE as one argument).

Upstream PR (not merged yet):
https://github.com/zmanda/amanda/pull/194

https://github.com/MaherAzzouzi/CVE-2022-37705
https://github.com/zmanda/amanda/issues/192
https://marc.info/?l=amanda-hackers&m=167437716918603&w=2

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-37705
https://bugzilla.redhat.com/show_bug.cgi?id=2167744
Comment 1 Thomas Leroy 2023-02-08 08:35:53 UTC
Affected:
- SUSE:SLE-11:Update
- openSUSE:Factory
- openSUSE:Backports:SLE-15-SP3
- openSUSE:Backports:SLE-15-SP4
Comment 3 Daniel Garcia 2023-02-21 07:17:59 UTC
Backporst for 15.3 is no longer supported.
Comment 4 OBSbugzilla Bot 2023-02-21 08:05:03 UTC
This is an autogenerated message for OBS integration:
This bug (1208032) was mentioned in
https://build.opensuse.org/request/show/1066928 Backports:SLE-15-SP4 / amanda
Comment 7 Swamp Workflow Management 2023-03-14 17:05:55 UTC
openSUSE-SU-2023:0069-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1208032,1208033
CVE References: CVE-2022-37704,CVE-2022-37705
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP4 (src):    amanda-3.5.1-bp154.3.3.1
Comment 8 Robert Frohl 2024-05-03 13:57:26 UTC
done, closing