CVE-2019-14866

Name
CVE-2019-14866
Description
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14866
Mailing List https://lists.gnu.org/archive/html/bug-cpio/2019-08/msg00003.html
Exploit https://lists.gnu.org/archive/html/bug-cpio/2019-11/msg00000.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:cpio:*:*:*:*:*:*:*:* cpio >= None < 2.13

Vulnerable and fixed packages

Source package Branch Version Maintainer Status