PT-2016-1311 · Gnu+3 · Cpio+3
Gustavo Grieco
·
Publicado
2015-12-14
·
Atualizado
2024-06-15
·
CVE-2016-2037
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
cpio version 2.11
Description
The issue is related to the cpio safer name suffix function in the cpio utility, which allows remote attackers to cause a denial of service due to an out-of-bounds write. This can be achieved by exploiting the function with a crafted cpio file, potentially leading to a buffer overflow. The exploitation of this issue may result in a denial of service.
Recommendations
For cpio version 2.11, consider avoiding the use of the cpio safer name suffix function until a patch is available. As a temporary workaround, restrict the processing of crafted cpio files to minimize the risk of exploitation.
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Ubuntu
Cpio