PT-2016-1311 · Gnu+3 · Cpio+3
Gustavo Grieco
·
Published
2015-12-14
·
Updated
2024-06-15
·
CVE-2016-2037
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
cpio version 2.11
Description
The issue is related to the cpio safer name suffix function in the cpio utility, which allows remote attackers to cause a denial of service due to an out-of-bounds write. This can be achieved by exploiting the function with a crafted cpio file, potentially leading to a buffer overflow. The exploitation of this issue may result in a denial of service.
Recommendations
For cpio version 2.11, consider avoiding the use of the cpio safer name suffix function until a patch is available. As a temporary workaround, restrict the processing of crafted cpio files to minimize the risk of exploitation.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Suse
Ubuntu
Cpio