Directory Traversal Vulnerability in cpio 2.11 by GNU
CVE-2015-1197

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
19 February 2015

Summary

The cpio 2.11 utility, when invoked with the --no-absolute-filenames option, is vulnerable to a directory traversal attack. This weakness allows local users to exploit symbolic links to overwrite arbitrary files on the system. By manipulating archive files, attackers can direct cpio to extract files into unintended locations, potentially leading to unauthorized file modifications or system instability. Users should ensure that cpio is updated to a secure version to mitigate this risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.