zmanda / amanda

Amanda Network Backup
https://www.zmanda.com/downloads/
Other
222 stars 107 forks source link

CVE-2022-37704 - privilege escalation from root to amandbackup using R… #202

Closed seetharaman-rajagopal closed 1 year ago

seetharaman-rajagopal commented 1 year ago

Issue : Dump can be manipulated by an attacker through the RSH environment variable, which is used to specify the shell binary to be used for remote backups. By manipulating this variable and invoking Dump via rundump, an attacker can execute arbitrary code with root privileges.

Fix: Filter the RSH environmental settings being passed to DUMP program