First published: Thu Feb 06 2014(Updated: )
cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Cpio | ||
SUSE Linux | =2007.05.10 | |
SUSE Linux | =2010.07.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4226 is considered a moderate severity vulnerability due to its potential to allow unauthorized file overwrites.
To fix CVE-2010-4226, update to the latest version of GNU cpio or the appropriate patched version from your distribution.
CVE-2010-4226 affects systems using GNU cpio, specifically openSUSE versions 2007.05.10 and 2010.07.28.
Yes, CVE-2010-4226 can be exploited by remote attackers via a specially crafted RPM package containing symlinks.
The potential impact of CVE-2010-4226 includes unauthorized file modifications, which can lead to further vulnerabilities or data loss.