Red Hat Bugzilla – Bug 163096
cpio - CAN-2005-1111 race and CAN-2005-1229 directory traversal issues
Last modified: 2007-04-18 13:29:17 EDT
Description of problem:
Bug #155751 and bug #156314 describe problems detailed in CAN-2005-1111
and CAN-2005-1229. This is different than bug #152891. A version of cpio
with these fixed is included in FC4 set.
For RHEL 7.3 there is a new source package at
with two patches "ported" from cpio-2.6-7 (FC4). This changes semantics.
An old '--no-absolute-filenames' is still recognized, although not documented,
but this is a default which can be changed with new '--absolute-filenames'.
These issues affect all other versions of cpio below 2.6-7.
Red Hat Linux and Fedora Core releases <=4 are now completely unmaintained.
These bugs can't be fixed in these versions. If the issue still persists in
current Fedora Core releases, please reopen. Thank you, and sorry about this.