Bugzilla – Bug 1203390
VUL-0: CVE-2022-37703: amanda: information leak vulnerability in the calcsize SUID binary
Last modified: 2023-03-21 15:51:17 UTC
CVE-2022-37703 In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use `opendir()` as root directly without checking the path, letting the attacker provide an arbitrary path. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-37703 https://www.cve.org/CVERecord?id=CVE-2022-37703 https://github.com/MaherAzzouzi/CVE-2022-37703 http://www.amanda.org/
No fix upstream afaics Affected: - SUSE:SLE-11:Update - openSUSE:Backports:SLE-15-SP3:Update - openSUSE:Backports:SLE-15-SP4:Update - openSUSE:Factory
Upstream report: https://github.com/zmanda/amanda/issues/192
Upstream fix merged in upstream master: https://github.com/zmanda/amanda/commit/cf01041d34b830fc8bfe87346a9a1aa092d76820