CVE-2015-1197: Low severity gnu cpio vulnerability
Published Jan 5, 2015
·Updated
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
Affected Software
2 affected componentsFixes available
debian/cpio
2.13+dfsg-7.1~deb11u12.13+dfsg-7.12.15+dfsg-2
GNU cpio=2.11
Event History
Jan 5, 2015
Data Sourced
via Debian·09:54 PM
SeverityAffected Software
Feb 19, 2015
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1197?
CVE-2015-1197 is classified as a medium severity vulnerability due to its potential for local users to exploit the symlink attack.
2
How do I fix CVE-2015-1197?
To fix CVE-2015-1197, upgrade GNU cpio to version 2.13 or later.
3
Who is affected by CVE-2015-1197?
Local users of GNU cpio version 2.11 are affected by CVE-2015-1197.
4
What is the impact of CVE-2015-1197?
The impact of CVE-2015-1197 allows local users to write to arbitrary files through a symlink attack.
5
What versions of GNU cpio are vulnerable to CVE-2015-1197?
GNU cpio version 2.11 is specifically vulnerable to CVE-2015-1197.