Back

MEDIUM

amanda: runtar: crafted arguments can lead to local privilege escalation

Published Apr 16, 2023

Description

A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerable component is the runtar SUID program, which is a wrapper to run /usr/bin/tar with specific arguments that are controllable by the attacker. This program mishandles the arguments passed to tar binary (it expects that the argument name and value are separated with a space; however, separating them with an equals sign is also supported),

Affected products

Remediation

Red Hat statement

This flaw has been rated Low on Red Hat Enterprise Linux since unprivileged users can't pass arbitrary arguments to the `runtar` SUID binary. By default, only users in the "disk" group can execute the `runtar` binary on RHEL.

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 16, 2023
Updated Nov 4, 2025
Reserved Aug 8, 2022
CISA Vulnrichment
Updated Nov 27, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 7, 2023
ENISA EUVD
Assigner mitre
Published Apr 16, 2023
Updated Nov 4, 2025
Exploited since n/a
EUVD-2022-40319