CVE-2005-1229: Medium severity GNU cpio vulnerability
Published Apr 22, 2005
·Updated
Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file.
Affected Software
1 affected component
GNU cpio<=2.6
Event History
Apr 22, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1229?
CVE-2005-1229 is considered to have a medium severity due to its ability to allow remote attackers to write to arbitrary directories.
2
How do I fix CVE-2005-1229?
To fix CVE-2005-1229, update GNU cpio to version 2.6 or later, as earlier versions are vulnerable.
3
What systems are affected by CVE-2005-1229?
CVE-2005-1229 affects GNU cpio versions 2.6 and earlier, which can be found in various Linux distributions.
4
What type of vulnerability is CVE-2005-1229?
CVE-2005-1229 is a directory traversal vulnerability that can be exploited to write files outside the intended directory.
5
Can CVE-2005-1229 be exploited remotely?
Yes, CVE-2005-1229 can be exploited by remote attackers through specially crafted cpio files.