VYPR

cpio

by Cpio

CVEs (4)

  • CVE-2019-14866HigJan 7, 2020
    risk 0.48cvss 7.3epss 0.01

    In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths…

  • CVE-2015-1197Feb 19, 2015
    risk 0.00cvss epss 0.03

    cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.

  • CVE-2005-4268Dec 15, 2005
    risk 0.00cvss epss 0.01

    Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a file whose size is represented by more than 8 digits.

  • CVE-2005-1229May 2, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file.