{"id":"UBUNTU-CVE-2022-37703","details":"In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use `opendir()` as root directly without checking the path, letting the attacker provide an arbitrary path.","modified":"2026-02-04T04:01:40.671283Z","published":"2022-09-13T20:15:00Z","related":["USN-5966-3"],"upstream":["CVE-2022-37703"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-37703"},{"type":"REPORT","url":"http://www.amanda.org/"},{"type":"REPORT","url":"https://github.com/MaherAzzouzi/CVE-2022-37703"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5966-3"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-37703"}],"affected":[{"package":{"name":"amanda","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/amanda@1:3.3.6-4.1ubuntu0.1+esm2?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:3.3.6-4","1:3.3.6-4.1","1:3.3.6-4.1ubuntu0.1","1:3.3.6-4.1ubuntu0.1+actuallyesm2","1:3.3.6-4.1ubuntu0.1+esm1","1:3.3.6-4.1ubuntu0.1+esm2"],"ecosystem_specific":{"binaries":[{"binary_name":"amanda-client","binary_version":"1:3.3.6-4.1ubuntu0.1+esm2"},{"binary_name":"amanda-common","binary_version":"1:3.3.6-4.1ubuntu0.1+esm2"},{"binary_name":"amanda-server","binary_version":"1:3.3.6-4.1ubuntu0.1+esm2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37703.json"}},{"package":{"name":"amanda","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/amanda@1:3.5.1-1ubuntu0.3?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:3.5.1-1ubuntu0.3"}]}],"versions":["1:3.3.9-5build1","1:3.5-2","1:3.5.1-1","1:3.5.1-1build1","1:3.5.1-1build2","1:3.5.1-1ubuntu0.1","1:3.5.1-1ubuntu0.2"],"ecosystem_specific":{"binaries":[{"binary_name":"amanda-client","binary_version":"1:3.5.1-1ubuntu0.3"},{"binary_name":"amanda-common","binary_version":"1:3.5.1-1ubuntu0.3"},{"binary_name":"amanda-server","binary_version":"1:3.5.1-1ubuntu0.3"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37703.json"}},{"package":{"name":"amanda","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/amanda@1:3.5.1-2ubuntu0.3?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:3.5.1-2ubuntu0.3"}]}],"versions":["1:3.5.1-2build2","1:3.5.1-2build3","1:3.5.1-2ubuntu0.1","1:3.5.1-2ubuntu0.2"],"ecosystem_specific":{"binaries":[{"binary_name":"amanda-client","binary_version":"1:3.5.1-2ubuntu0.3"},{"binary_name":"amanda-common","binary_version":"1:3.5.1-2ubuntu0.3"},{"binary_name":"amanda-server","binary_version":"1:3.5.1-2ubuntu0.3"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37703.json"}},{"package":{"name":"amanda","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/amanda@1:3.5.1-8ubuntu1.3?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:3.5.1-8ubuntu1.3"}]}],"versions":["1:3.5.1-5ubuntu1","1:3.5.1-8","1:3.5.1-8ubuntu1","1:3.5.1-8ubuntu1.1","1:3.5.1-8ubuntu1.2"],"ecosystem_specific":{"binaries":[{"binary_name":"amanda-client","binary_version":"1:3.5.1-8ubuntu1.3"},{"binary_name":"amanda-common","binary_version":"1:3.5.1-8ubuntu1.3"},{"binary_name":"amanda-server","binary_version":"1:3.5.1-8ubuntu1.3"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37703.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"low"}]}