Home/Product/gnu cpio
Product

gnu cpio

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-7207
all versions
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caus
4.9MEDIUM
CVE-2023-7216
all versions
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a
5.3MEDIUM
CVE-2021-38185
<= 2.13
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr int
7.8HIGH
CVE-2019-14866
< 2.13
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to crea
7.3HIGH
CVE-2016-2037
all versions
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds wri
6.5MEDIUM
CVE-2015-1197
all versions
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a
CVE-2014-9112
all versions
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service v
CVE-2010-4226
all versions
cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files v
7.2HIGH
CVE-2010-0624
<= 2.10
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and
CVE-2005-4268
all versions
Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of servi
CVE-2005-1229
<= 2.6
Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot
CVE-2005-1111
<= 2.6
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a fil
4.7MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin