zmanda / amanda

Amanda Network Backup
https://www.zmanda.com/downloads/
Other
214 stars 107 forks source link

Fix for CVE-2023-30577 #228

Closed rishabh-trivedi98 closed 11 months ago

rishabh-trivedi98 commented 1 year ago

Whitelisting only the required arguments for runtar so that someone cannot exploit CVE-2023-30577 vulnerability

prajwaltr93 commented 11 months ago

fix is for another scenario that was still exploitable with similar type of argument passing technique to runtar.c CVE-2023-30577