Known Vulnerabilities for Cpio by Gnu
Listed below are 10 of the newest known vulnerabilities associated with "Cpio" by "Gnu".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-38185 | GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetst... | 7.8 - HIGH | 2021-08-08 | 2023-06-04 |
| CVE-2019-14866 | In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to... | 7.3 - HIGH | 2020-01-07 | 2023-06-04 |
| CVE-2016-2037 | The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bound... | 6.5 - MEDIUM | 2016-02-22 | 2016-12-06 |
| CVE-2015-1197 | cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack... | 1.9 - LOW | 2015-02-19 | 2023-12-27 |
| CVE-2014-9112 | Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of serv... | 5 - MEDIUM | 2014-12-02 | 2017-09-08 |
| CVE-2010-4226 | cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary fi... | 5 - MEDIUM | 2014-02-06 | 2014-02-07 |
| CVE-2010-0624 | Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.2... | 6.8 - MEDIUM | 2010-03-15 | 2018-10-10 |
| CVE-2005-4268 | Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of ... | 3.7 - LOW | 2005-12-15 | 2018-10-03 |
| CVE-2005-1229 | Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. ... | 4.6 - MEDIUM | 2005-05-02 | 2017-07-11 |
| CVE-2005-1111 | Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on ... | 4.7 - MEDIUM | 2005-05-02 | 2024-01-26 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Cpio | 2.9 | All | All | All |
| Application | Gnu | Cpio | 2.8 | All | All | All |
| Application | Gnu | Cpio | 2.7 | All | All | All |
| Application | Gnu | Cpio | 2.6 | All | All | All |
| Application | Gnu | Cpio | 2.5.90 | All | All | All |
| Application | Gnu | Cpio | 2.5 | All | All | All |
| Application | Gnu | Cpio | 2.4-2 | All | All | All |
| Application | Gnu | Cpio | 2.13 | All | All | All |
| Application | Gnu | Cpio | 2.12 | All | All | All |
| Application | Gnu | Cpio | 2.11 | All | All | All |
| Application | Gnu | Cpio | 2.10 | All | All | All |
| Application | Gnu | Cpio | 1.3 | All | All | All |
| Application | Gnu | Cpio | 1.2 | All | All | All |
| Application | Gnu | Cpio | 1.1 | All | All | All |
| Application | Gnu | Cpio | 1.0 | All | All | All |
| Application | Gnu | Cpio | - | All | All | All |