Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2023-7207
Disclosure Date: February 29, 2024 (last updated February 29, 2024)
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
0
Attacker Value
Unknown
CVE-2016-2037
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
0
Attacker Value
Unknown
CVE-2014-9112
Disclosure Date: December 02, 2014 (last updated October 05, 2023)
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.
0
Attacker Value
Unknown
CVE-2005-1111
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
0