cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
References
Configurations
Information
Published : 2015-02-19 07:59
Updated : 2022-10-20 10:15
NVD link : CVE-2015-1197
Mitre link : CVE-2015-1197
JSON object : View
CWE
Products Affected
gnu
- cpio