RHSA-2010:0144: Moderate: cpio security update
GNU cpio copies files into or out of a cpio or tar archive.A heap-based buffer overflow flaw was found in the way cpio expandedarchive files. If a user were tricked into expanding a specially-craftedarchive, it could cause the cpio executable to crash or execute arbitrarycode with the privileges of the user running cpio. (CVE-2010-0624)Red Hat would like to thank Jakob Lell for responsibly reporting theCVE-2010-0624 issue.A denial of service flaw was found in the way cpio expanded archive files.If a user expanded a specially-crafted archive, it could cause the cpioexecutable to crash. (CVE-2007-4476)Users of cpio are advised to upgrade to this updated package, whichcontains backported patches to correct these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0144?
The severity of RHSA-2010:0144 is classified as moderate.
How do I fix RHSA-2010:0144?
To fix RHSA-2010:0144, update the cpio package to version 2.6-23.el5_4.1 or later.
What is the nature of the vulnerability in RHSA-2010:0144?
RHSA-2010:0144 describes a heap-based buffer overflow flaw in the cpio tool when expanding specially-crafted archive files.
Which versions of cpio are affected by RHSA-2010:0144?
Versions of cpio prior to 2.6-23.el5_4.1 are affected by RHSA-2010:0144.
Can RHSA-2010:0144 lead to system compromise?
Yes, if exploited, RHSA-2010:0144 can potentially allow an attacker to execute arbitrary code.