Lucene search

K
ubuntuUbuntuUSN-6755-1
HistoryApr 29, 2024 - 12:00 a.m.

GNU cpio vulnerabilities

2024-04-2900:00:00
ubuntu.com
8
gnu cpio
path traversal
arbitrary files

4.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.5%

Releases

  • Ubuntu 23.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS

Packages

  • cpio - a tool to manage archives of files

Details

Ingo Brückl discovered that cpio contained a path traversal vulnerability.
If a user or automated system were tricked into extracting a specially
crafted cpio archive, an attacker could possibly use this issue to write
arbitrary files outside the target directory on the host, even if using the
option --no-absolute-filenames.

OSVersionArchitecturePackageVersionFilename
Ubuntu23.10noarchcpio< 2.13+dfsg-7.1ubuntu0.1UNKNOWN
Ubuntu23.10noarchcpio-win32< 2.13+dfsg-7.1ubuntu0.1UNKNOWN
Ubuntu22.04noarchcpio< 2.13+dfsg-7ubuntu0.1UNKNOWN
Ubuntu22.04noarchcpio-win32< 2.13+dfsg-7ubuntu0.1UNKNOWN
Ubuntu20.04noarchcpio< 2.13+dfsg-2ubuntu0.4UNKNOWN
Ubuntu20.04noarchcpio-win32< 2.13+dfsg-2ubuntu0.4UNKNOWN

4.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.5%