Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-1197

Опубликовано: 19 фев. 2015
Источник: debian

Описание

cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cpiofixed2.11+dfsg-4.1package
cpiono-dsawheezypackage
cpiono-dsasqueezepackage

Примечания

  • Patch used in SUSE: https://bugzilla.suse.com/attachment.cgi?id=599460&action=diff

  • https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=45b0ee2b407913c533f7ded8d6f8cbeec16ff6ca

  • Regression in upstream's handling of patch https://bugs.debian.org/946267

Связанные уязвимости

ubuntu
почти 11 лет назад

cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.

redhat
около 11 лет назад

cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.

nvd
почти 11 лет назад

cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.

github
больше 3 лет назад

cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.