Bug 2266856 (CVE-2023-7207) - CVE-2023-7207 cpio: path traversal vulnerability
Summary: CVE-2023-7207 cpio: path traversal vulnerability
Keywords:
Status: NEW
Alias: CVE-2023-7207
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2266859
Blocks: 2266853
TreeView+ depends on / blocked
 
Reported: 2024-02-29 07:44 UTC by Rohit Keshri
Modified: 2024-04-02 17:18 UTC (History)
9 users (show)

Fixed In Version: cpio 2.14
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Rohit Keshri 2024-02-29 07:44:52 UTC
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

References:
https://www.openwall.com/lists/oss-security/2023/12/21/8
https://www.openwall.com/lists/oss-security/2024/01/05/1

Upstream patch:
https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=376d663340a9dc91c91a5849e5713f07571c1628

Comment 1 Rohit Keshri 2024-02-29 07:46:03 UTC
Created cpio tracking bugs for this issue:

Affects: fedora-all [bug 2266859]


Note You need to log in before you can comment on or make changes to this bug.