CVE-2005-1229
published 2005-05-02CVE-2005-1229: Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file.
PriorityP425medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
1.88%
77.0th percentile
Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cpio | < cpio 2.6-6 (bookworm) | cpio 2.6-6 (bookworm) |
| gnu | cpio | <= 2.6 | — |
| gnu | cpio | >= 0 < 2.6-6 | 2.6-6 |
| gnu | cpio | >= 0 < 2.6-6 | 2.6-6 |
| gnu | cpio | >= 0 < 2.6-6 | 2.6-6 |
| gnu | cpio | >= 0 < 2.6-6 | 2.6-6 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-06:03.cpio: Multiple vulnerabilities cpio
bsd_advisories·2006-01-11·CVSS 4.7
CVE-2005-1111 [MEDIUM] FreeBSD-SA-06:03.cpio: Multiple vulnerabilities cpio
FreeBSD-SA-06:03.cpio Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities cpio
Category: contrib
Module: contrib_cpio
Announced: 2006-01-11
Credits: Imran Ghory, Richard Harms
Affects: All FreeBSD releases.
Corrected: 2006-01-11 08:02:16 UTC (RELENG_6, 6.0-STABLE)
2006-01-11 08:03:18 UTC (RELENG_6_0, 6.0-RELEASE-p2)
2006-01-11 08:03:55 UTC (RELENG_5, 5.4-STABLE)
2006-01-11 08:04:33 UTC (RELENG_5_4, 5.4-RELEASE-p9)
2006-01-11 08:05:54 UTC (RELENG_5_3, 5.3-RELEASE-p24)
2006-01-11 08:06:47 UTC (RELENG_4, 4.11-STABLE)
2006-01-11 08:07:18 UTC (RELENG_4_11, 4.11-RELEASE-p14)
2006-01-11 08:08:08 UTC (RELENG_4_10, 4.10-RELEASE-p20)
CVE Name: CVE-2005-1111, CVE-2005-1229, CVE-2005-4268
For general information regarding FreeBSD Security Advisories,
including descriptions of the
Ubuntu
cpio vulnerabilities
vendor_ubuntu·2005-09-29
CVE-2005-1111 cpio vulnerabilities
Title: cpio vulnerabilities
Summary: cpio vulnerabilities
Imran Ghory found a race condition in the handling of output files.
While a file was unpacked with cpio, a local attacker with write
permissions to the target directory could exploit this to change the
permissions of arbitrary files of the cpio user. (CAN-2005-1111)
Imran Ghory discovered a path traversal vulnerability. Even when the
--no-absolute-filenames option was specified, cpio did not filter out
".." path components. By tricking an user into unpacking a malicious
cpio archive, this could be exploited to install files in arbitrary
paths with the privileges of the user calling cpio. (CAN-2005-1229)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cpio directory traversal issue
vendor_redhat·2005-04-20·CVSS 4.6
CVE-2005-1229 [MEDIUM] cpio directory traversal issue
cpio directory traversal issue
Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file.
Statement: This is defined and documented behaviour:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=156313
Debian
CVE-2005-1229: cpio - Directory traversal vulnerability in cpio 2.6 and earlier allows remote attacker...
vendor_debian·2005·CVSS 4.6
CVE-2005-1229 [MEDIUM] CVE-2005-1229: cpio - Directory traversal vulnerability in cpio 2.6 and earlier allows remote attacker...
Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file.
Scope: local
bookworm: resolved (fixed in 2.6-6)
bullseye: resolved (fixed in 2.6-6)
forky: resolved (fixed in 2.6-6)
sid: resolved (fixed in 2.6-6)
trixie: resolved (fixed in 2.6-6)
GHSA
GHSA-g564-fjp3-fqpr: Directory traversal vulnerability in cpio 2
ghsa_unreviewed·2022-05-03
CVE-2005-1229 [MEDIUM] GHSA-g564-fjp3-fqpr: Directory traversal vulnerability in cpio 2
Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file.
OSV
CVE-2005-1229: Directory traversal vulnerability in cpio 2
osv·2005-05-02·CVSS 4.6
CVE-2005-1229 [MEDIUM] CVE-2005-1229: Directory traversal vulnerability in cpio 2
Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file.
No detection rules found.
No public exploits indexed.
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:03.cpio.ascftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.2/SCOSA-2006.2.txtftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.32/SCOSA-2005.32.txthttp://lists.suse.com/archive/suse-security-announce/2006-May/0004.htmlhttp://marc.info/?l=bugtraq&m=111403177526312&w=2http://secunia.com/advisories/16998http://secunia.com/advisories/17123http://secunia.com/advisories/18290http://secunia.com/advisories/18395http://secunia.com/advisories/20117http://secunia.com/advisories/27857http://www.debian.org/security/2005/dsa-846http://www.mandriva.com/security/advisories?name=MDKSA-2007:233http://www.osvdb.org/17939http://www.securityfocus.com/bid/13291http://www.ubuntu.com/usn/usn-189-1https://exchange.xforce.ibmcloud.com/vulnerabilities/20204ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:03.cpio.ascftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.2/SCOSA-2006.2.txtftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.32/SCOSA-2005.32.txthttp://lists.suse.com/archive/suse-security-announce/2006-May/0004.htmlhttp://marc.info/?l=bugtraq&m=111403177526312&w=2http://secunia.com/advisories/16998http://secunia.com/advisories/17123http://secunia.com/advisories/18290http://secunia.com/advisories/18395http://secunia.com/advisories/20117http://secunia.com/advisories/27857http://www.debian.org/security/2005/dsa-846http://www.mandriva.com/security/advisories?name=MDKSA-2007:233http://www.osvdb.org/17939http://www.securityfocus.com/bid/13291http://www.ubuntu.com/usn/usn-189-1https://exchange.xforce.ibmcloud.com/vulnerabilities/20204
2005-05-02
Published