First published: Mon Jan 05 2015(Updated: )
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/cpio | 2.13+dfsg-7.1~deb11u1 2.13+dfsg-7.1 2.15+dfsg-2 | |
GNU Cpio | =2.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1197 is classified as a medium severity vulnerability due to its potential for local users to exploit the symlink attack.
To fix CVE-2015-1197, upgrade GNU cpio to version 2.13 or later.
Local users of GNU cpio version 2.11 are affected by CVE-2015-1197.
The impact of CVE-2015-1197 allows local users to write to arbitrary files through a symlink attack.
GNU cpio version 2.11 is specifically vulnerable to CVE-2015-1197.