Package "cpio"
| Name: |
cpio
|
Description: |
This package is just an umbrella for a group of other packages,
it has no description. Description samples from packages in group:
- GNU cpio -- a program to manage archives of files (win32 build)
|
| Latest version: |
2.13+dfsg-7ubuntu0.2 |
| Release: |
jammy (22.04) |
| Level: |
updates |
| Repository: |
universe |
Links
Other versions of "cpio" in Jammy
Packages in group
Deleted packages are displayed in grey.
Changelog
|
cpio (2.13+dfsg-7ubuntu0.2) jammy-security; urgency=medium
* SECURITY UPDATE: Unbounded stack allocation
- debian/patches/CVE-2026-66485.patch: Minor fixes in src/makepath.c,
src/userspec.c.
- CVE-2026-66485
* SECURITY UPDATE: Hard link to file outside intended directory
- debian/patches/CVE-2026-66484.patch: The --no-absolute-filenames option
affects hard link targets too. in src/tar.c.
- CVE-2026-66484
* SECURITY UPDATE: Unescaped output
- debian/patches/CVE-2026-66486.patch: Quote file names in error messages
and in listings. in src/copyin.c, src/copyout.c, src/copypass.c,
src/main.c, tests/CVE-2019-14866.at, tests/testsuite.
- CVE-2026-66486
-- Isabel Garcia Contreras Tue, 18 Aug 2026 16:46:57 -0400
|
| Source diff to previous version |
| CVE-2026-66485 |
GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack m |
| CVE-2026-66484 |
GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the |
| CVE-2026-66486 |
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio |
| CVE-2019-14866 |
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives fro |
|
|
cpio (2.13+dfsg-7ubuntu0.1) jammy-security; urgency=medium
* SECURITY UPDATE: Path traversal vulnerability
- debian/patches/CVE-2023-7207.patch: Create symlink placeholder
if --no-absolute-filenames was given and replace placeholders
after extraction.
- debian/patches/revert-CVE-2015-1197-handling.patch: Removed.
- CVE-2023-7207
-- Fabian Toepfer <email address hidden> Sun, 28 Apr 2024 14:30:36 +0200
|
| CVE-2023-7207 |
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in |
| CVE-2015-1197 |
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive |
|
About
-
Send Feedback to @ubuntu_updates