CVE-2014-9112
published 2014-12-02CVE-2014-9112: Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a…
PriorityP432medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
7.09%
93.5th percentile
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cpio | < cpio 2.11+dfsg-4 (bookworm) | cpio 2.11+dfsg-4 (bookworm) |
| debian | debian_linux | — | — |
| gnu | cpio | — | — |
| gnu | cpio | >= 0 < 2.11+dfsg-4 | 2.11+dfsg-4 |
| gnu | cpio | >= 0 < 2.11+dfsg-4 | 2.11+dfsg-4 |
| gnu | cpio | >= 0 < 2.11+dfsg-4 | 2.11+dfsg-4 |
| gnu | cpio | >= 0 < 2.11+dfsg-4 | 2.11+dfsg-4 |
| gnu | cpio | >= 0 < 2.11+dfsg-1ubuntu1.1 | 2.11+dfsg-1ubuntu1.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv6.8MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU cpio vulnerabilities
vendor_ubuntu·2015-01-08·CVSS 6.8
CVE-2010-0624 [MEDIUM] GNU cpio vulnerabilities
Title: GNU cpio vulnerabilities
Summary: The GNU cpio program could be made to crash or run programs if it
opened a specially crafted file or received specially crafted input.
Michal Zalewski discovered an out of bounds write issue in the
process_copy_in function of GNU cpio. An attacker could specially
craft a cpio archive that could create a denial of service or possibly
execute arbitrary code. (CVE-2014-9112)
Jakob Lell discovered a heap-based buffer overflow in the rmt_read__
function of GNU cpio's rmt client functionality. An attacker
controlling a remote rmt server could use this to cause a denial of
service or possibly execute arbitrary code. This issue only affected
Ubuntu 10.04 LTS. (CVE-2010-0624)
Instructions: In general, a standard system update will make all the necessary
Red Hat
cpio: heap-based buffer overflow flaw in list_file()
vendor_redhat·2014-11-23·CVSS 5.0
CVE-2014-9112 [MEDIUM] CWE-122 cpio: heap-based buffer overflow flaw in list_file()
cpio: heap-based buffer overflow flaw in list_file()
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.
A heap-based buffer overflow flaw was found in cpio's list_file() function. An attacker could provide a specially crafted archive that, when processed by cpio, would crash cpio, or potentially lead to arbitrary code execution.
Package: cpio (Red Hat Enterprise Linux 5) - Will not fix
Package: cpio (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2014-9112: cpio - Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allo...
vendor_debian·2014·CVSS 5.0
CVE-2014-9112 [MEDIUM] CVE-2014-9112: cpio - Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allo...
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.
Scope: local
bookworm: resolved (fixed in 2.11+dfsg-4)
bullseye: resolved (fixed in 2.11+dfsg-4)
forky: resolved (fixed in 2.11+dfsg-4)
sid: resolved (fixed in 2.11+dfsg-4)
trixie: resolved (fixed in 2.11+dfsg-4)
GHSA
GHSA-wvrh-73qw-9vj9: Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2
ghsa_unreviewed·2022-05-17
CVE-2014-9112 [MEDIUM] CWE-119 GHSA-wvrh-73qw-9vj9: Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.
OSV
cpio vulnerabilities
osv·2015-01-08·CVSS 6.8
CVE-2014-9112 [MEDIUM] cpio vulnerabilities
cpio vulnerabilities
Michal Zalewski discovered an out of bounds write issue in the
process_copy_in function of GNU cpio. An attacker could specially
craft a cpio archive that could create a denial of service or possibly
execute arbitrary code. (CVE-2014-9112)
Jakob Lell discovered a heap-based buffer overflow in the rmt_read__
function of GNU cpio's rmt client functionality. An attacker
controlling a remote rmt server could use this to cause a denial of
service or possibly execute arbitrary code. This issue only affected
Ubuntu 10.04 LTS. (CVE-2010-0624)
OSV
CVE-2014-9112: Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2
osv·2014-12-02·CVSS 5.0
CVE-2014-9112 [MEDIUM] CVE-2014-9112: Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.
No detection rules found.
No public exploits indexed.
http://seclists.org/fulldisclosure/2014/Nov/74http://secunia.com/advisories/60167http://secunia.com/advisories/62145http://www.debian.org/security/2014/dsa-3111http://www.openwall.com/lists/oss-security/2014/11/23/2http://www.openwall.com/lists/oss-security/2014/11/25/2http://www.openwall.com/lists/oss-security/2014/11/26/20http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/71248http://www.ubuntu.com/usn/USN-2456-1https://exchange.xforce.ibmcloud.com/vulnerabilities/98918https://savannah.gnu.org/bugs/?43709http://seclists.org/fulldisclosure/2014/Nov/74http://secunia.com/advisories/60167http://secunia.com/advisories/62145http://www.debian.org/security/2014/dsa-3111http://www.openwall.com/lists/oss-security/2014/11/23/2http://www.openwall.com/lists/oss-security/2014/11/25/2http://www.openwall.com/lists/oss-security/2014/11/26/20http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/71248http://www.ubuntu.com/usn/USN-2456-1https://exchange.xforce.ibmcloud.com/vulnerabilities/98918https://savannah.gnu.org/bugs/?43709
2014-12-02
Published