Lucene search

K
archlinuxArch LinuxASA-201501-5
HistoryJan 14, 2015 - 12:00 a.m.

cpio: heap buffer overflow

2015-01-1400:00:00
Arch Linux
lists.archlinux.org
27

0.022 Low

EPSS

Percentile

89.5%

A heap-based buffer overflow flaw was reported in cpio’s list_file()
function. Attempting to extract a malicious cpio archive could cause
cpio to crash or, potentially, execute arbitrary code.
As noted in the original report, this issue could be trigger via other
utilities, such as when running "less".

OSVersionArchitecturePackageVersionFilename
anyanyanycpio< 2.11-5UNKNOWN