CVE-2019-14866

NameCVE-2019-14866
DescriptionIn all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-1981-1, DLA-3445-1, ELA-187-1, ELA-863-1
Debian Bugs941412

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cpio (PTS)jessie, jessie (lts)2.11+dfsg-4.1+deb8u4fixed
stretch (lts), stretch2.11+dfsg-6+deb9u1fixed
buster (security), buster, buster (lts)2.12+dfsg-9+deb10u1fixed
bullseye2.13+dfsg-7.1~deb11u1fixed
bookworm2.13+dfsg-7.1fixed
sid, trixie2.15+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cpiosourcewheezy2.11+dfsg-0.1+deb7u3ELA-187-1
cpiosourcejessie2.11+dfsg-4.1+deb8u4ELA-863-1
cpiosourcestretch2.11+dfsg-6+deb9u1ELA-863-1
cpiosourcebuster2.12+dfsg-9+deb10u1DLA-3445-1
cpiosource(unstable)2.13+dfsg-1low941412

Notes

[stretch] - cpio <no-dsa> (Minor issue)
https://lists.gnu.org/archive/html/bug-cpio/2019-08/msg00003.html
http://git.savannah.gnu.org/cgit/cpio.git/commit/?id=7554e3e42cd72f6f8304410c47fe6f8918e9bfd7

Search for package or bug name: Reporting problems