CVE-2005-4268
published 2005-12-15CVE-2005-4268: Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly…
PriorityP414low3.7CVSS 2.0
AVLACHAuNCPIPAP
EPSS
0.54%
42.0th percentile
Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a file whose size is represented by more than 8 digits.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cpio | < cpio 2.6-10 (bookworm) | cpio 2.6-10 (bookworm) |
| gnu | cpio | — | — |
| gnu | cpio | >= 0 < 2.6-10 | 2.6-10 |
| gnu | cpio | >= 0 < 2.6-10 | 2.6-10 |
| gnu | cpio | >= 0 < 2.6-10 | 2.6-10 |
| gnu | cpio | >= 0 < 2.6-10 | 2.6-10 |
CVSS provenance
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
osv3.7LOW
vendor_debian3.7MEDIUM
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-06:03.cpio: Multiple vulnerabilities cpio
bsd_advisories·2006-01-11·CVSS 4.7
CVE-2005-1111 [MEDIUM] FreeBSD-SA-06:03.cpio: Multiple vulnerabilities cpio
FreeBSD-SA-06:03.cpio Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities cpio
Category: contrib
Module: contrib_cpio
Announced: 2006-01-11
Credits: Imran Ghory, Richard Harms
Affects: All FreeBSD releases.
Corrected: 2006-01-11 08:02:16 UTC (RELENG_6, 6.0-STABLE)
2006-01-11 08:03:18 UTC (RELENG_6_0, 6.0-RELEASE-p2)
2006-01-11 08:03:55 UTC (RELENG_5, 5.4-STABLE)
2006-01-11 08:04:33 UTC (RELENG_5_4, 5.4-RELEASE-p9)
2006-01-11 08:05:54 UTC (RELENG_5_3, 5.3-RELEASE-p24)
2006-01-11 08:06:47 UTC (RELENG_4, 4.11-STABLE)
2006-01-11 08:07:18 UTC (RELENG_4_11, 4.11-RELEASE-p14)
2006-01-11 08:08:08 UTC (RELENG_4_10, 4.10-RELEASE-p20)
CVE Name: CVE-2005-1111, CVE-2005-1229, CVE-2005-4268
For general information regarding FreeBSD Security Advisories,
including descriptions of the
Ubuntu
cpio vulnerability
vendor_ubuntu·2006-01-03
CVE-2005-4268 cpio vulnerability
Title: cpio vulnerability
Summary: cpio vulnerability
Richard Harms discovered that cpio did not sufficiently validate file
properties when creating archives. Files with e. g. a very large size
caused a buffer overflow. By tricking a user or an automatic backup
system into putting a specially crafted file into a cpio archive, a
local attacker could probably exploit this to execute arbitrary code
with the privileges of the target user (which is likely root in an
automatic backup system).
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cpio large filesize buffer overflow
vendor_redhat·2005-11-07·CVSS 3.7
CVE-2005-4268 [LOW] cpio large filesize buffer overflow
cpio large filesize buffer overflow
Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a file whose size is represented by more than 8 digits.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2005-4268: cpio - Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio arch...
vendor_debian·2005·CVSS 3.7
CVE-2005-4268 [LOW] CVE-2005-4268: cpio - Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio arch...
Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a file whose size is represented by more than 8 digits.
Scope: local
bookworm: resolved (fixed in 2.6-10)
bullseye: resolved (fixed in 2.6-10)
forky: resolved (fixed in 2.6-10)
sid: resolved (fixed in 2.6-10)
trixie: resolved (fixed in 2.6-10)
GHSA
GHSA-gf47-4488-9gh6: Buffer overflow in cpio 2
ghsa_unreviewed·2022-05-03
CVE-2005-4268 [LOW] CWE-119 GHSA-gf47-4488-9gh6: Buffer overflow in cpio 2
Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a file whose size is represented by more than 8 digits.
OSV
CVE-2005-4268: Buffer overflow in cpio 2
osv·2005-12-15·CVSS 3.7
CVE-2005-4268 [LOW] CVE-2005-4268: Buffer overflow in cpio 2
Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a file whose size is represented by more than 8 digits.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-4268 cpio large filesize buffer overflow
bugzilla·2007-02-19·CVSS 3.7
CVE-2005-4268 [LOW] CVE-2005-4268 cpio large filesize buffer overflow
CVE-2005-4268 cpio large filesize buffer overflow
Clone for rhel3/rhel2.1
+++ This bug was initially created as a clone of Bug #172669 +++
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.7.12) Gecko/20050922
Fedora/1.0.7-1.1.fc4 Firefox/1.0.7
Description of problem:
The latest update to cpio is being killed after a buffer overflow is detected.
Version-Release number of selected component (if applicable):
cpio-2.6-8.FC4
How reproducible:
Always
Steps to Reproduce:
cpio is given a large hierarchy of files and started using "cpio -o --format=crc"
-- Additional comment from [email protected] on 2005-11-10 09:03 EST --
char ascii_header[112];
...
sprintf (ascii_header,
"%6s%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx",
magic_stri
Bugzilla
CVE-2005-4268 cpio large filesize buffer overflow
bugzilla·2005-11-10·CVSS 3.7
CVE-2005-4268 [LOW] CVE-2005-4268 cpio large filesize buffer overflow
CVE-2005-4268 cpio large filesize buffer overflow
+++ This bug was initially created as a clone of Bug #172669 +++
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.7.12) Gecko/20050922
Fedora/1.0.7-1.1.fc4 Firefox/1.0.7
Description of problem:
The latest update to cpio is being killed after a buffer overflow is detected.
Version-Release number of selected component (if applicable):
cpio-2.6-8.FC4
How reproducible:
Always
Steps to Reproduce:
cpio is given a large hierarchy of files and started using "cpio -o --format=crc"
-- Additional comment from [email protected] on 2005-11-10 09:03 EST --
char ascii_header[112];
...
sprintf (ascii_header,
"%6s%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx",
magic_string,
file_hdr->c_ino, file
Bugzilla
CVE-2005-4268 cpio large filesize buffer overflow
bugzilla·2005-11-08·CVSS 3.7
CVE-2005-4268 [LOW] CVE-2005-4268 cpio large filesize buffer overflow
CVE-2005-4268 cpio large filesize buffer overflow
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.7.12) Gecko/20050922 Fedora/1.0.7-1.1.fc4 Firefox/1.0.7
Description of problem:
The latest update to cpio is being killed after a buffer overflow is detected.
Version-Release number of selected component (if applicable):
cpio-2.6-8.FC4
How reproducible:
Always
Steps to Reproduce:
cpio is given a large hierarchy of files and started using "cpio -o --format=crc"
Actual Results: *** buffer overflow detected ***: cpio terminated
======= Backtrace: =========
/lib64/libc.so.6(__chk_fail+0x2f)[0x3a2e5dcb6f]
/lib64/libc.so.6[0x3a2e5dc149]
/lib64/libc.so.6(_IO_default_xsputn+0x86)[0x3a2e567b26]
/lib64/libc.so.6(_IO_padn+0x62)[0x3a2e55d532]
/lib64/libc.so.6(_IO_v
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:03.cpio.aschttp://frontal1.mandriva.com/security/advisories?name=MDKSA-2005:237http://lists.suse.com/archive/suse-security-announce/2006-May/0004.htmlhttp://secunia.com/advisories/18251http://secunia.com/advisories/18278http://secunia.com/advisories/18280http://secunia.com/advisories/18395http://secunia.com/advisories/20117http://secunia.com/advisories/25098http://secunia.com/advisories/25161http://www.osvdb.org/22194http://www.redhat.com/support/errata/RHSA-2007-0245.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0145.htmlhttp://www.securityfocus.com/bid/16057https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=172669https://exchange.xforce.ibmcloud.com/vulnerabilities/23855https://issues.rpath.com/browse/RPL-1338https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10450https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6860https://usn.ubuntu.com/234-1/ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:03.cpio.aschttp://frontal1.mandriva.com/security/advisories?name=MDKSA-2005:237http://lists.suse.com/archive/suse-security-announce/2006-May/0004.htmlhttp://secunia.com/advisories/18251http://secunia.com/advisories/18278http://secunia.com/advisories/18280http://secunia.com/advisories/18395http://secunia.com/advisories/20117http://secunia.com/advisories/25098http://secunia.com/advisories/25161http://www.osvdb.org/22194http://www.redhat.com/support/errata/RHSA-2007-0245.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0145.htmlhttp://www.securityfocus.com/bid/16057https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=172669https://exchange.xforce.ibmcloud.com/vulnerabilities/23855https://issues.rpath.com/browse/RPL-1338https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10450https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6860https://usn.ubuntu.com/234-1/
2005-12-15
Published