Lucene search

K
debianDebianDEBIAN:DLA-111-1:B5528
HistoryDec 15, 2014 - 2:18 p.m.

[SECURITY] [DLA 111-1] cpio security update

2014-12-1514:18:40
lists.debian.org
13

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.8 Medium

AI Score

Confidence

High

0.022 Low

EPSS

Percentile

89.5%

Package : cpio
Version : 2.11-4+deb6u1
CVE ID : CVE-2014-9112
Debian Bug : 772793

Multiple issues have been identified in cpio, including a buffer overflow
and multiple NULL pointer dereference, resulting at least in a denial of
service and possibly also in an unwanted code execution.

This has been fixed in Debian 6 Squeeze with version 2.11-4+deb6u1 by
applying the upstream patches.

RaphaΓ«l Hertzog β—ˆ Debian Developer

Support Debian LTS: http://www.freexian.com/services/debian-lts.html
Learn to master Debian: http://debian-handbook.info/get/
Attachment:
signature.asc
Description: Digital signature

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.8 Medium

AI Score

Confidence

High

0.022 Low

EPSS

Percentile

89.5%