Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-7207

Опубликовано: 29 фев. 2024
Источник: debian

Описание

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cpiofixed2.14+dfsg-1package
cpiono-dsabookwormpackage
cpiono-dsabullseyepackage
cpionot-affectedbusterpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2023/12/21/8

  • Fixed by: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=376d663340a9dc91c91a5849e5713f07571c1628 (v2.14)

Связанные уязвимости

CVSS3: 4.9
ubuntu
почти 2 года назад

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

CVSS3: 5.5
redhat
около 2 лет назад

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

CVSS3: 4.9
nvd
почти 2 года назад

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

msrc
5 месяцев назад

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

suse-cvrf
почти 2 года назад

Security update for cpio