Vulnerability Name:

CVE-2016-10729 (CCN-151981)

Assigned:2016-01-11
Published:2016-01-11
Updated:2019-01-09
Summary:An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
7.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
7.1 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-77
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2016-10729

Source: CCN
Type: Amanda Web site
Amanda

Source: XF
Type: UNKNOWN
amanda-cve201610729-priv-esc(151981)

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [01-11-2016]

Source: EXPLOIT-DB
Type: Exploit, Third Party Advisory, VDB Entry
39217

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2016-10729

Vulnerable Configuration:Configuration 1:
  • cpe:/a:zmanda:amanda:3.3.1:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:zmanda:amanda:3.3.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201610729
    V
    CVE-2016-10729
    2022-09-02
    oval:org.opensuse.security:def:34007
    P
    Security update for webkit2gtk3 (Important)
    2021-12-01
    oval:org.opensuse.security:def:33743
    P
    Security update for webkit2gtk3 (Important)
    2021-11-23
    oval:org.opensuse.security:def:32207
    P
    Security update for util-linux (Moderate)
    2021-10-19
    oval:org.opensuse.security:def:34553
    P
    Security update for libvirt (Moderate)
    2021-10-04
    oval:org.opensuse.security:def:33958
    P
    Security update for fetchmail (Moderate)
    2021-08-18
    oval:org.opensuse.security:def:32131
    P
    Security update for ovmf (Important)
    2021-06-22
    oval:org.opensuse.security:def:32947
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-15
    oval:org.opensuse.security:def:32119
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-15
    oval:org.opensuse.security:def:33655
    P
    Security update for curl (Moderate)
    2021-05-27
    oval:org.opensuse.security:def:33900
    P
    Security update for java-1_7_0-openjdk (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:30066
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:32903
    P
    Security update for apache-commons-io (Moderate)
    2021-04-26
    oval:org.opensuse.security:def:29347
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:34046
    P
    Security update for openssl-1_1 (Important)
    2021-03-25
    oval:org.opensuse.security:def:34652
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:29478
    P
    Security update for python-cryptography (Important)
    2021-03-02
    oval:org.opensuse.security:def:30022
    P
    Security update for openvswitch (Important)
    2021-02-12
    oval:org.opensuse.security:def:32120
    P
    Security update for ImageMagick (Important)
    2021-01-22
    oval:org.opensuse.security:def:30003
    P
    Security update for dnsmasq (Important)
    2021-01-19
    oval:org.opensuse.security:def:34417
    P
    Security update for the Linux Kernel (Important)
    2021-01-15
    oval:org.opensuse.security:def:32841
    P
    Security update for xen (Moderate)
    2020-12-29
    oval:org.opensuse.security:def:29964
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:33624
    P
    Security update for openssh (Moderate)
    2020-12-16
    oval:org.opensuse.security:def:34333
    P
    Security update for openssl-1_1 (Important)
    2020-12-10
    oval:org.opensuse.security:def:31083
    P
    Security update for python-cryptography (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:35855
    P
    NetworkManager-gnome-0.7.1-5.22.28 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35814
    P
    pyxml-0.8.4-194.23.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:34322
    P
    Security update for xen (Important)
    2020-12-03
    oval:org.opensuse.security:def:28121
    P
    Security update for gdk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30763
    P
    Security update for apport (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34071
    P
    Security update for libxml2 (Low)
    2020-12-01
    oval:org.opensuse.security:def:34321
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:29622
    P
    Security update for bsdtar (Important)
    2020-12-01
    oval:org.opensuse.security:def:32880
    P
    gzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28402
    P
    Security update for spice (Important)
    2020-12-01
    oval:org.opensuse.security:def:31023
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:34793
    P
    Security update for amanda (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29915
    P
    Security update for libcgroup1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33585
    P
    Security update for MozillaFirefox, mozilla-nss, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:33286
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28695
    P
    Security update for gimp
    2020-12-01
    oval:org.opensuse.security:def:31127
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:34709
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30311
    P
    Security update for tcpdump (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33598
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:28837
    P
    Security update for telepathy-idle
    2020-12-01
    oval:org.opensuse.security:def:32341
    P
    Security update for spice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35017
    P
    Security update for grub2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:30741
    P
    Security update for amanda (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30397
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:29536
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:29276
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:32579
    P
    mozilla-xulrunner190 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35132
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:28110
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:30676
    P
    Security update for ImageMagick (Low)
    2020-12-01
    oval:org.opensuse.security:def:29565
    P
    Security update for OpenEXR (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28317
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30974
    P
    Security update for gtk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34753
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:29860
    P
    Security update for the Linux Kernel
    2020-12-01
    oval:org.opensuse.security:def:33275
    P
    tomcat6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28543
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:33502
    P
    Security update for mutt
    2020-12-01
    oval:org.opensuse.security:def:28798
    P
    Security update for OpenSLP
    2020-12-01
    oval:org.opensuse.security:def:31803
    P
    Security update for amanda (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34958
    P
    Security update for freeradius-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30704
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:30323
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28898
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:29265
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:32492
    P
    boost-license on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35105
    P
    Security update for the Linux Kernel (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28109
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:30619
    P
    Security update for wireshark
    2020-12-01
    oval:org.opensuse.security:def:32792
    P
    sysstat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28187
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30918
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34115
    P
    Security update for nagios-nrpe (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29707
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:33274
    P
    tgt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28459
    P
    Security update for xfsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31062
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:33367
    P
    Security update for sblim-sfcb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28749
    P
    Security update for lzo
    2020-12-01
    oval:org.opensuse.security:def:31765
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:34799
    P
    Security update for ansible (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30312
    P
    Security update for tcpdump (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28854
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:29264
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:32435
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:35066
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:30529
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29572
    P
    Security update for amanda (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32735
    P
    libtiff3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35176
    P
    Security update for kvm (Important)
    2020-12-01
    oval:com.ubuntu.xenial:def:2016107290000000
    V
    CVE-2016-10729 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-10-24
    oval:com.ubuntu.bionic:def:201610729000
    V
    CVE-2016-10729 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-10-24
    oval:com.ubuntu.disco:def:2016107290000000
    V
    CVE-2016-10729 on Ubuntu 19.04 (disco) - medium.
    2018-10-24
    oval:com.ubuntu.cosmic:def:201610729000
    V
    CVE-2016-10729 on Ubuntu 18.10 (cosmic) - medium.
    2018-10-24
    oval:com.ubuntu.cosmic:def:2016107290000000
    V
    CVE-2016-10729 on Ubuntu 18.10 (cosmic) - medium.
    2018-10-24
    oval:com.ubuntu.trusty:def:201610729000
    V
    CVE-2016-10729 on Ubuntu 14.04 LTS (trusty) - medium.
    2018-10-24
    oval:com.ubuntu.bionic:def:2016107290000000
    V
    CVE-2016-10729 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-10-24
    oval:com.ubuntu.xenial:def:201610729000
    V
    CVE-2016-10729 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-10-24
    BACK
    zmanda amanda 3.3.1
    redhat enterprise linux 7.0
    debian debian linux 7.0
    debian debian linux 8.0
    debian debian linux 9.0
    debian debian linux 10.0
    zmanda amanda 3.3.1