CVE-2014-9112: Buffer Overflow
Published Dec 2, 2014
·Updated
Heap-based buffer overflow in the processcopyin function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.
Affected Software
2 affected components
GNU cpio=2.11
Debian Debian Linux=7.0
Event History
Dec 2, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9112?
CVE-2014-9112 is considered a medium severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2014-9112?
To fix CVE-2014-9112, update GNU Cpio to version 2.12 or later.
3
What are the potential impacts of CVE-2014-9112?
The potential impacts of CVE-2014-9112 include remote denial of service when processing specially crafted cpio archives.
4
Which systems are affected by CVE-2014-9112?
CVE-2014-9112 affects GNU Cpio version 2.11 and Debian Linux version 7.0.
5
Can CVE-2014-9112 be exploited remotely?
Yes, CVE-2014-9112 can be exploited remotely by sending specially crafted cpio archives to the vulnerable system.