Severity
5.0MEDIUM
EPSS
1.3%
top 19.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 2
Latest updateMay 17

Description

Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

Debiancpio< 2.11+dfsg-4+3
Ubuntucpio< 2.11+dfsg-1ubuntu1.1
NVDgnu/cpio2.11

Also affects: Debian Linux 7.0

🔴Vulnerability Details

4
GHSA
GHSA-wvrh-73qw-9vj9: Heap-based buffer overflow in the process_copy_in function in GNU Cpio 22022-05-17
OSV
cpio vulnerabilities2015-01-08
CVEList
CVE-2014-9112: Heap-based buffer overflow in the process_copy_in function in GNU Cpio 22014-12-02
OSV
CVE-2014-9112: Heap-based buffer overflow in the process_copy_in function in GNU Cpio 22014-12-02

📋Vendor Advisories

3
Ubuntu
GNU cpio vulnerabilities2015-01-08
Red Hat
cpio: heap-based buffer overflow flaw in list_file()2014-11-23
Debian
CVE-2014-9112: cpio - Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allo...2014

💬Community

1
Bugzilla
CVE-2014-9112 cpio: heap-based buffer overflow flaw in list_file()2014-11-25