First published: Fri Apr 22 2005(Updated: )
Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU cpio | <=2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1229 is considered to have a medium severity due to its ability to allow remote attackers to write to arbitrary directories.
To fix CVE-2005-1229, update GNU cpio to version 2.6 or later, as earlier versions are vulnerable.
CVE-2005-1229 affects GNU cpio versions 2.6 and earlier, which can be found in various Linux distributions.
CVE-2005-1229 is a directory traversal vulnerability that can be exploited to write files outside the intended directory.
Yes, CVE-2005-1229 can be exploited by remote attackers through specially crafted cpio files.