CVE-2022-37703

CVE-2022-37703

In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use `opendir()` as root directly without checking the path, letting the attacker provide an arbitrary path.

Source: CVE-2022-37703

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다