Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-7207

Опубликовано: 29 фев. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.9

Описание

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

2.15+dfsg-1ubuntu1
esm-infra-legacy/trusty

not-affected

see notes
esm-infra/bionic

not-affected

see notes
esm-infra/focal

released

2.13+dfsg-2ubuntu0.4
esm-infra/xenial

not-affected

see notes
focal

released

2.13+dfsg-2ubuntu0.4
jammy

released

2.13+dfsg-7ubuntu0.1
lunar

ignored

end of life, was needed
mantic

released

2.13+dfsg-7.1ubuntu0.1

Показывать по

EPSS

Процентиль: 19%
0.00061
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
около 2 лет назад

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

CVSS3: 4.9
nvd
почти 2 года назад

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

msrc
5 месяцев назад

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

CVSS3: 4.9
debian
почти 2 года назад

Debian's cpio contains a path traversal vulnerability. This issue was ...

suse-cvrf
почти 2 года назад

Security update for cpio

EPSS

Процентиль: 19%
0.00061
Низкий

4.9 Medium

CVSS3