Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-2037

Опубликовано: 22 фев. 2016
Источник: debian

Описание

The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cpiofixed2.11+dfsg-5package

Примечания

  • https://www.openwall.com/lists/oss-security/2016/01/19/4

  • To reproduce and uncover the issue with unstable version compile with ASAN

  • Patch: https://lists.gnu.org/archive/html/bug-cpio/2016-01/msg00005.html

  • https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=d36ec5f4e93130efb24fb9678aafd88e8070095b

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 10 лет назад

The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.

CVSS3: 4.3
redhat
около 10 лет назад

The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.

CVSS3: 6.5
nvd
почти 10 лет назад

The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.

suse-cvrf
около 9 лет назад

Security update for cpio

suse-cvrf
около 9 лет назад

Security update for cpio