CVE-2015-1197

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
19 February 2015

Summary

cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.