VendorsGNUcpio2.11
Vulnerabilities

GNU cpio 2.11

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2016-2037
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
Published 2016-02-22 · Modified
6.5EPSS 0.055
CVE-2014-9112
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.
Published 2014-12-02 · Modified
5.0EPSS 0.071
CVE-2015-1197
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
Published 2015-02-19 · Modified
1.9EPSS 0.029