Back to search
CVE-2022-37703
Published: Sep 13, 2022
Modified: Nov 4, 2025
PUBLISHED
Description
In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use `opendir()` as root directly without checking the path, letting the attacker provide an arbitrary path.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2023-3d0619d767
vendor-advisory
FEDORA-2023-1293196f34
vendor-advisory
FEDORA-2023-e295804b3d
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now