GNU cpio 2.13

CPE Details

GNU cpio 2.13
2.13
2020-01-10
16h19 +00:00
2020-01-10
16h19 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:gnu:cpio:2.13:*:*:*:*:*:*:*

Informations

Vendor

gnu

Product

cpio

Version

2.13

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-38185 2021-08-06 22h00 +00:00 GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.
7.8
High
CVE-2010-4226 2014-02-06 15h00 +00:00 cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.
5