Directory Traversal Vulnerability in cpio 2.11 by GNU
CVE-2015-1197
Currently unrated
Summary
The cpio 2.11 utility, when invoked with the --no-absolute-filenames option, is vulnerable to a directory traversal attack. This weakness allows local users to exploit symbolic links to overwrite arbitrary files on the system. By manipulating archive files, attackers can direct cpio to extract files into unintended locations, potentially leading to unauthorized file modifications or system instability. Users should ensure that cpio is updated to a secure version to mitigate this risk.
References
Timeline
Vulnerability published
Vulnerability Reserved