PT-2016-1311 · Gnu+3 · Cpio+3

Gustavo Grieco

·

Publicado

2015-12-14

·

Atualizado

2024-06-15

·

CVE-2016-2037

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions cpio version 2.11
Description The issue is related to the cpio safer name suffix function in the cpio utility, which allows remote attackers to cause a denial of service due to an out-of-bounds write. This can be achieved by exploiting the function with a crafted cpio file, potentially leading to a buffer overflow. The exploitation of this issue may result in a denial of service.
Recommendations For cpio version 2.11, consider avoiding the use of the cpio safer name suffix function until a patch is available. As a temporary workaround, restrict the processing of crafted cpio files to minimize the risk of exploitation.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-2097
BDU:2016-00608
CVE-2016-2037
DLA-415-1
DSA-3483-1
MGASA-2016-0063
OPENSUSE-SU-2024:10143-1
SUSE-SU-2017:0366-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
SUSE-SU-2017_0366-1
USN-2906-1

Produtos afetados

Alt Linux
Suse
Ubuntu
Cpio