CVE-2015-1197

NameCVE-2015-1197
Descriptioncpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs774669

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cpio (PTS)jessie, jessie (lts)2.11+dfsg-4.1+deb8u4fixed
stretch (lts), stretch2.11+dfsg-6+deb9u1fixed
buster (security), buster, buster (lts)2.12+dfsg-9+deb10u1fixed
bullseye2.13+dfsg-7.1~deb11u1fixed
bookworm2.13+dfsg-7.1fixed
sid, trixie2.15+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cpiosource(unstable)2.11+dfsg-4.1low774669

Notes

[wheezy] - cpio <no-dsa> (Minor issue)
[squeeze] - cpio <no-dsa> (Minor issue)
Patch used in SUSE: https://bugzilla.suse.com/attachment.cgi?id=599460&action=diff
https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=45b0ee2b407913c533f7ded8d6f8cbeec16ff6ca
Regression in upstream's handling of patch https://bugs.debian.org/946267

Search for package or bug name: Reporting problems