Medium severity4.7NVD Advisory· Published May 2, 2005· Updated Apr 16, 2026
CVE-2005-1111
CVE-2005-1111
Description
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
Affected products
5cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:4.10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:4.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:5.04:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
19- www.debian.org/security/2005/dsa-846nvdThird Party Advisory
- www.securityfocus.com/bid/13159nvdBroken LinkThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/usn-189-1nvdThird Party Advisory
- ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:03.cpio.ascnvdBroken Link
- ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.2/SCOSA-2006.2.txtnvdBroken Link
- ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.32/SCOSA-2005.32.txtnvdBroken Link
- lists.suse.com/archive/suse-security-announce/2006-May/0004.htmlnvdBroken Link
- marc.infonvdMailing List
- secunia.com/advisories/16998nvdBroken Link
- secunia.com/advisories/17123nvdBroken Link
- secunia.com/advisories/17532nvdBroken Link
- secunia.com/advisories/18290nvdBroken Link
- secunia.com/advisories/18395nvdBroken Link
- secunia.com/advisories/20117nvdBroken Link
- www.osvdb.org/15725nvdBroken Link
- www.redhat.com/support/errata/RHSA-2005-378.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2005-806.htmlnvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A358nvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9783nvdBroken Link
News mentions
0No linked articles in our index yet.