CVE-2023-7207
- EPSS 0.06%
- Published 29.02.2024 01:42:59
- Last modified 26.08.2025 17:19:09
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
CVE-2023-7216
- EPSS 0.18%
- Published 05.02.2024 15:15:08
- Last modified 21.11.2024 08:45:32
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside...
CVE-2021-38185
- EPSS 27.84%
- Published 08.08.2021 00:15:07
- Last modified 09.06.2025 15:15:26
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pa...
CVE-2019-14866
- EPSS 0.03%
- Published 07.01.2020 17:15:11
- Last modified 21.11.2024 04:27:32
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attack...
CVE-2016-2037
- EPSS 19.45%
- Published 22.02.2016 15:59:00
- Last modified 12.04.2025 10:46:40
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
CVE-2015-1197
- EPSS 3.61%
- Published 19.02.2015 15:59:12
- Last modified 12.04.2025 10:46:40
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
- EPSS 1.34%
- Published 02.12.2014 16:59:05
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.
- EPSS 0.51%
- Published 06.02.2014 17:00:03
- Last modified 09.06.2025 15:15:22
cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.
CVE-2010-0624
- EPSS 1.86%
- Published 15.03.2010 13:28:25
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arb...
CVE-2005-4268
- EPSS 0.05%
- Published 15.12.2005 18:11:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a file whose size is represented by more than 8 digits.