CVE-2015-1197

NameCVE-2015-1197
Descriptioncpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitylow (attack range: local)
Debian Bugs774669

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cpio (PTS)jessie (security), jessie2.11+dfsg-4.1+deb8u1fixed
stretch2.11+dfsg-6fixed
bullseye, sid, buster2.12+dfsg-9fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cpiosource(unstable)2.11+dfsg-4.1low774669

Notes

[wheezy] - cpio <no-dsa> (Minor issue)
[squeeze] - cpio <no-dsa> (Minor issue)
Patch used in SUSE: https://bugzilla.suse.com/attachment.cgi?id=599460&action=diff

Search for package or bug name: Reporting problems