Lucene search

K
redhatRedHatRHSA-2010:0144
HistoryMar 15, 2010 - 12:00 a.m.

(RHSA-2010:0144) Moderate: cpio security update

2010-03-1500:00:00
access.redhat.com
13

0.014 Low

EPSS

Percentile

86.5%

GNU cpio copies files into or out of a cpio or tar archive.

A heap-based buffer overflow flaw was found in the way cpio expanded
archive files. If a user were tricked into expanding a specially-crafted
archive, it could cause the cpio executable to crash or execute arbitrary
code with the privileges of the user running cpio. (CVE-2010-0624)

Red Hat would like to thank Jakob Lell for responsibly reporting the
CVE-2010-0624 issue.

A denial of service flaw was found in the way cpio expanded archive files.
If a user expanded a specially-crafted archive, it could cause the cpio
executable to crash. (CVE-2007-4476)

Users of cpio are advised to upgrade to this updated package, which
contains backported patches to correct these issues.