Bug 1213701 (CVE-2023-30577) - VUL-0: CVE-2023-30577: amanda: Improper argument checking for runtar.c
Summary: VUL-0: CVE-2023-30577: amanda: Improper argument checking for runtar.c
Status: NEW
Alias: CVE-2023-30577
Product: openSUSE Distribution
Classification: openSUSE
Component: Other (show other bugs)
Version: Leap 15.5
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: E-mail List
URL: https://smash.suse.de/issue/373489/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-07-27 07:00 UTC by Gianluca Gabrielli
Modified: 2023-08-04 22:05 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gianluca Gabrielli 2023-07-27 07:00:40 UTC
AMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for runtar.c, a different vulnerability than CVE-2022-37705.

References:

https://github.com/zmanda/amanda/releases/tag/tag-community-3.5.4
https://github.com/zmanda/amanda/pull/228
Comment 1 Gianluca Gabrielli 2023-07-27 07:02:47 UTC
Supported codestreams are only in OBS:

 - openSUSE:Backports:SLE-15-SP4/amanda
 - openSUSE:Backports:SLE-15-SP5/amanda
 - openSUSE:Factory/amanda

Upstream patch at a2c37406 [0].

[0] https://github.com/zmanda/amanda/commit/a2c374069516a90548c67a028d0463470d2b1376.patch
Comment 2 Petr Gajdos 2023-07-28 12:24:38 UTC
Darin and all, please see

Factory:
https://build.opensuse.org/request/show/1101187
B15sp5:
https://build.opensuse.org/request/show/1101189
B15sp4:
https://build.opensuse.org/request/show/1101190

Danilo is on leave currently; I will be on leave next weeks, so don't wait for me, if something wrong.
Comment 3 Danilo Spinella 2023-08-01 13:37:00 UTC
Thank you Petr for working on this issue. Assigning to security.
Comment 4 Marcus Meissner 2023-08-04 22:05:27 UTC
openSUSE-SU-2023:0205-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1213701
CVE References: CVE-2023-30577
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    amanda-3.5.2-bp155.2.3.1
Comment 5 Marcus Meissner 2023-08-04 22:05:57 UTC
openSUSE-SU-2023:0206-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1213701
CVE References: CVE-2023-30577
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP4 (src):    amanda-3.5.1-bp154.3.6.1