Логотип exploitDog
bind:"BDU:2020-01329" OR bind:"CVE-2019-14866"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2020-01329" OR bind:"CVE-2019-14866"

Количество 14

Количество 14

fstec логотип

BDU:2020-01329

почти 6 лет назад

Уязвимость утилиты архивирования Сpio, связанная с ошибками при проверке заголовка TAR-файла, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.7
EPSS: Низкий
redos логотип

ROS-20250825-01

4 месяца назад

Уязвимость cpio

CVSS3: 6.7
EPSS: Низкий
ubuntu логотип

CVE-2019-14866

почти 6 лет назад

In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2019-14866

больше 6 лет назад

In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2019-14866

почти 6 лет назад

In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2019-14866

почти 6 лет назад

In all versions of cpio before 2.13 does not properly validate input f ...

CVSS3: 7.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2596-1

около 6 лет назад

Security update for cpio

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2593-1

около 6 лет назад

Security update for cpio

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:3064-1

около 6 лет назад

Security update for cpio

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:3059-1

около 6 лет назад

Security update for cpio

EPSS: Низкий
rocky логотип

RLSA-2021:1582

больше 4 лет назад

Moderate: cpio security update

EPSS: Низкий
github логотип

GHSA-g3pr-277r-xcx7

больше 3 лет назад

In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.

CVSS3: 7.3
EPSS: Низкий
oracle-oval логотип

ELSA-2021-1582

больше 4 лет назад

ELSA-2021-1582: cpio security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-3908

около 5 лет назад

ELSA-2020-3908: cpio security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2020-01329

Уязвимость утилиты архивирования Сpio, связанная с ошибками при проверке заголовка TAR-файла, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.7
0%
Низкий
почти 6 лет назад
redos логотип
ROS-20250825-01

Уязвимость cpio

CVSS3: 6.7
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2019-14866

In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.

CVSS3: 7.3
0%
Низкий
почти 6 лет назад
redhat логотип
CVE-2019-14866

In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.

CVSS3: 6.7
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-14866

In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.

CVSS3: 7.3
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-14866

In all versions of cpio before 2.13 does not properly validate input f ...

CVSS3: 7.3
0%
Низкий
почти 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2596-1

Security update for cpio

0%
Низкий
около 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2593-1

Security update for cpio

0%
Низкий
около 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:3064-1

Security update for cpio

0%
Низкий
около 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:3059-1

Security update for cpio

0%
Низкий
около 6 лет назад
rocky логотип
RLSA-2021:1582

Moderate: cpio security update

0%
Низкий
больше 4 лет назад
github логотип
GHSA-g3pr-277r-xcx7

In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2021-1582

ELSA-2021-1582: cpio security update (MODERATE)

больше 4 лет назад
oracle-oval логотип
ELSA-2020-3908

ELSA-2020-3908: cpio security update (MODERATE)

около 5 лет назад

Уязвимостей на страницу