Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27464
HistoryOct 01, 2020 - 3:53 a.m.

Arbitrary File Rewrite

2020-10-0103:53:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
cpio package vulnerability
arbitrary file rewrite
input validation issue
tar generation vulnerability

EPSS

0.001

Percentile

21.2%

The cpio packages is vulnerable to arbitrary file rewrite. Improper input validation when writing tar header fields leads to unexpect tar generation.