PT-1996-1073 · Debian+1 · Cpio+1
Published
1996-07-16
·
Updated
2017-10-19
·
CVE-1999-1572
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
cpio on FreeBSD version 2.1.0
cpio on Debian GNU/Linux version 3.0
Description
The issue allows local users to read or overwrite files created by cpio due to the use of a 0 umask when creating files with the -O or -F options, resulting in files being created with mode 0666.
Recommendations
For cpio on FreeBSD version 2.1.0, consider changing the umask to a more restrictive setting to prevent unauthorized access to files created with the -O or -F options.
For cpio on Debian GNU/Linux version 3.0, consider changing the umask to a more restrictive setting to prevent unauthorized access to files created with the -O or -F options.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Cpio