CVE-2015-1197
published 2015-02-19CVE-2015-1197: cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
PriorityP421low1.9CVSS 2.0
AVLACMAuNCNIPAN
EXPLOIT
EPSS
2.91%
85.4th percentile
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cpio | < cpio 2.11+dfsg-4.1 (bookworm) | cpio 2.11+dfsg-4.1 (bookworm) |
| debian | cpio | < cpio 2.14+dfsg-1 (forky) | cpio 2.14+dfsg-1 (forky) |
| debian | debian_cpio | < 2.14+dfsg-1 | 2.14+dfsg-1 |
| gnu | cpio | — | — |
| gnu | cpio | — | — |
| gnu | cpio | >= 0 < 2.11+dfsg-4.1 | 2.11+dfsg-4.1 |
| gnu | cpio | >= 0 < 2.11+dfsg-4.1 | 2.11+dfsg-4.1 |
| gnu | cpio | >= 0 < 2.11+dfsg-4.1 | 2.11+dfsg-4.1 |
| gnu | cpio | >= 0 < 2.14+dfsg-1 | 2.14+dfsg-1 |
| gnu | cpio | >= 0 < 2.11+dfsg-4.1 | 2.11+dfsg-4.1 |
| gnu | cpio | >= 0 < 2.14+dfsg-1 | 2.14+dfsg-1 |
| gnu | cpio | >= 0 < 2.11+dfsg-1ubuntu1.2 | 2.11+dfsg-1ubuntu1.2 |
| msrc | cbl2_cpio_2.13-5_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
osv1.9LOW
vendor_msrc4.9MEDIUM
vendor_debian1.9LOW
vendor_redhat1.9LOW
vendor_ubuntu1.9LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x4gq-xcr8-xwp7: Debian's cpio contains a path traversal vulnerability
ghsa_unreviewed·2024-02-29·CVSS 1.9
CVE-2023-7207 [LOW] CWE-22 GHSA-x4gq-xcr8-xwp7: Debian's cpio contains a path traversal vulnerability
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
OSV
CVE-2023-7207: Debian's cpio contains a path traversal vulnerability
osv·2024-02-29·CVSS 1.9
CVE-2023-7207 [LOW] CVE-2023-7207: Debian's cpio contains a path traversal vulnerability
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
GHSA
GHSA-447h-6vgc-mg6p: cpio 2
ghsa_unreviewed·2022-05-17
CVE-2015-1197 [LOW] GHSA-447h-6vgc-mg6p: cpio 2
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
OSV
cpio vulnerabilities
osv·2016-02-22·CVSS 1.9
CVE-2015-1197 [LOW] cpio vulnerabilities
cpio vulnerabilities
Alexander Cherepanov discovered that GNU cpio incorrectly handled symbolic
links when used with the --no-absolute-filenames option. If a user or
automated system were tricked into extracting a specially-crafted cpio
archive, a remote attacker could possibly use this issue to write arbitrary
files. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2015-1197)
Gustavo Grieco discovered that GNU cpio incorrectly handled memory when
extracting archive files. If a user or automated system were tricked into
extracting a specially-crafted cpio archive, a remote attacker could use
this issue to cause GNU cpio to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2016-2037)
OSV
CVE-2015-1197: cpio 2
osv·2015-02-19·CVSS 1.9
CVE-2015-1197 [LOW] CVE-2015-1197: cpio 2
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
Microsoft
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provide
vendor_msrc·2024-01-09·CVSS 4.9
CVE-2023-7207 [LOW] CWE-22 Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provide
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional
Red Hat
cpio: path traversal vulnerability
vendor_redhat·2024-01-04·CVSS 1.9
CVE-2023-7207 [LOW] CWE-22 cpio: path traversal vulnerability
cpio: path traversal vulnerability
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
A flaw was found in cpio. The fix for CVE-2015-1197 created other issues, and the patch to fix this issue was reverted, causing a regression when the --no-absolute-filenames command line option is used, resulting in a path traversal vulnerability.
Mitigation: Do not process untrusted archives with the cpio program.
Package: cpio (Red Hat Enterprise Linux 6) - Out of support scope
Package: cpio (Red Hat Enterprise Linux 7) - Out of support scope
Package: cpio (Red Hat Enterprise Linux 8) - Will not fix
Package:
Debian
CVE-2023-7207: cpio - Debian's cpio contains a path traversal vulnerability. This issue was introduced...
vendor_debian·2023·CVSS 1.9
CVE-2023-7207 [LOW] CVE-2023-7207: cpio - Debian's cpio contains a path traversal vulnerability. This issue was introduced...
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.14+dfsg-1)
sid: resolved (fixed in 2.14+dfsg-1)
trixie: resolved (fixed in 2.14+dfsg-1)
Red Hat
cpio: --no-absolute-filenames bypass via symlinks
vendor_redhat·2017-06-05·CVSS 1.9
CVE-2017-7516 [LOW] CWE-22 cpio: --no-absolute-filenames bypass via symlinks
cpio: --no-absolute-filenames bypass via symlinks
[REJECTED CVE] A vulnerability was identified in the GNU cpio package where the --no-absolute-filenames option, intended to restrict extraction to the current directory, can be bypassed using crafted symlinks. During extraction, cpio will first create the symlink and then follow it for subsequent entries, allowing a malicious archive to write files outside the intended directory (e.g., /tmp/file). An attacker could exploit this by tricking a user, into extracting such an archive, potentially leading to arbitrary file creation, privilege escalation, or data corruption.
Statement: This flaw was found to be a duplicate of CVE-2015-1197. Please see https://access.redhat.com/security/cve/CVE-2015-1197 for information about affected products an
Ubuntu
GNU cpio vulnerabilities
vendor_ubuntu·2016-02-22·CVSS 1.9
CVE-2015-1197 [LOW] GNU cpio vulnerabilities
Title: GNU cpio vulnerabilities
Summary: Several security issues were fixed in GNU cpio.
Alexander Cherepanov discovered that GNU cpio incorrectly handled symbolic
links when used with the --no-absolute-filenames option. If a user or
automated system were tricked into extracting a specially-crafted cpio
archive, a remote attacker could possibly use this issue to write arbitrary
files. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2015-1197)
Gustavo Grieco discovered that GNU cpio incorrectly handled memory when
extracting archive files. If a user or automated system were tricked into
extracting a specially-crafted cpio archive, a remote attacker could use
this issue to cause GNU cpio to crash, resulting in a denial of service, or
possibly execute arbitrary code. (
Red Hat
cpio: directory traversal through symlinks
vendor_redhat·2015-01-05·CVSS 1.9
CVE-2015-1197 [LOW] CWE-59 cpio: directory traversal through symlinks
cpio: directory traversal through symlinks
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
Package: cpio (Red Hat Enterprise Linux 5) - Will not fix
Package: cpio (Red Hat Enterprise Linux 6) - Will not fix
Package: cpio (Red Hat Enterprise Linux 7) - Will not fix
Package: cpio (Red Hat Enterprise Linux 9) - Fix deferred
Debian
CVE-2015-1197: cpio - cpio 2.11, when using the --no-absolute-filenames option, allows local users to ...
vendor_debian·2015·CVSS 1.9
CVE-2015-1197 [LOW] CVE-2015-1197: cpio - cpio 2.11, when using the --no-absolute-filenames option, allows local users to ...
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
Scope: local
bookworm: resolved (fixed in 2.11+dfsg-4.1)
bullseye: resolved (fixed in 2.11+dfsg-4.1)
forky: resolved (fixed in 2.11+dfsg-4.1)
sid: resolved (fixed in 2.11+dfsg-4.1)
trixie: resolved (fixed in 2.11+dfsg-4.1)
No detection rules found.
Bugzilla
CVE-2017-7516 cpio: --no-absolute-filenames bypass via symlinks [fedora-all]
bugzilla·2018-01-29·CVSS 1.9
CVE-2017-7516 [LOW] CVE-2017-7516 cpio: --no-absolute-filenames bypass via symlinks [fedora-all]
CVE-2017-7516 cpio: --no-absolute-filenames bypass via symlinks [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1539685,1539688
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users restart after update
Bugzilla
CVE-2017-7516 cpio: --no-absolute-filenames bypass via symlinks
bugzilla·2018-01-29·CVSS 1.9
CVE-2017-7516 [LOW] CVE-2017-7516 cpio: --no-absolute-filenames bypass via symlinks
CVE-2017-7516 cpio: --no-absolute-filenames bypass via symlinks
Note: this bug is actually a duplicate of CVE-2015-1197. See CVE-2015-1197 for information regarding this.
A possible --no-absolute-filenames bypass while extracting a malicious archive in cpio. This allows for arbitrary file creation.
Discussion:
External References:
http://lists.gnu.org/archive/html/bug-cpio/2017-06/msg00001.html
---
Created cpio tracking bugs for this issue:
Affects: fedora-all [bug 1539688]
---
Acknowledgments:
Name: Cedric Buissart (Red Hat)
---
Hi Cedric,
Isn't that a duplicate of CVE-2015-1197?
Regards,
Salvatore
---
Sorry to be more specific, there are references in the MITRE entry at https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1197 .
https://lists.gnu.org/archive/html/bug
Bugzilla
CVE-2015-1197 CVE-2017-7516 cpio: various flaws [fedora-all]
bugzilla·2015-02-03·CVSS 1.9
CVE-2015-1197 [LOW] CVE-2015-1197 CVE-2017-7516 cpio: various flaws [fedora-all]
CVE-2015-1197 CVE-2017-7516 cpio: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While onl
Bugzilla
CVE-2015-1197 cpio: directory traversal through symlinks
bugzilla·2015-01-07·CVSS 1.9
CVE-2015-1197 [LOW] CVE-2015-1197 cpio: directory traversal through symlinks
CVE-2015-1197 cpio: directory traversal through symlinks
It was reported [1] that cpio is susceptible to a directory traversal vulnerability.
Original report follows:
...
While extracting an archive, it will extract symlinks and then follow them if
they are referenced in further entries. This can be exploited by a rogue
archive to write files outside the current directory.
Example:
1) create a sample archive:
ln -s /tmp dir
echo dir | cpio -oF test.cpio
rm dir
mkdir dir
echo hello > dir/file
echo dir/file | cpio -oAF test.cpio
rm -r dir
2) test it:
cpio --no-absolute-filenames -ivF test.cpio
This will create a symlink "dir" in the current directory and a file
"/tmp/file".
...
No patches are available at this time.
[1]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774669
Di
Securelist
Ongoing exploitation of CVE-2022-41352 (Zimbra 0-day)
blogs_securelist·2022-10-13·CVSS 1.9
CVE-2022-41352 [LOW] Ongoing exploitation of CVE-2022-41352 (Zimbra 0-day)
Table of Contents
- Overview
- Vulnerability details
- Mitigation
- Detection
- Remediation
Authors
- GReAT
## Overview
On September 10, 2022, a user reported on Zimbra’s official forums that their team detected a security incident originating from a fully patched instance of Zimbra. The details they provided allowed Zimbra to confirm that an unknown vulnerability allowed attackers to upload arbitrary files to up-to-date servers. At the moment, Zimbra has released a patch and shared its installation steps. In addition, manual mitigation steps can be undertaken by system administrators to prevent successful exploitation (see below).
Kaspersky investigated the threat and was able to confirm that unknown APT groups have actively been exploiting this vulnerability in the wild, one of wh
Securelist
Ongoing exploitation of CVE-2022-41352 (Zimbra 0-day)
blogs_securelist·2022-10-13·CVSS 1.9
[LOW] Ongoing exploitation of CVE-2022-41352 (Zimbra 0-day)
Table of Contents
Overview
Vulnerability details
Mitigation
Detection
Remediation
Authors
GReAT
## Overview
On September 10, 2022, a user reported on Zimbra’s official forums that their team detected a security incident originating from a fully patched instance of Zimbra. The details they provided allowed Zimbra to confirm that an unknown vulnerability allowed attackers to upload arbitrary files to up-to-date servers. At the moment, Zimbra has released a patch and shared its installation steps. In addition, manual mitigation steps can be undertaken by system administrators to prevent successful exploitation (see below).
Kaspersky investigated the threat and was able to confirm that unknown APT groups have actively been exploiting this vulnerability in the wild, one of which is sy
http://advisories.mageia.org/MGASA-2015-0080.htmlhttp://packetstormsecurity.com/files/169458/Zimbra-Collaboration-Suite-TAR-Path-Traversal.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:066http://www.openwall.com/lists/oss-security/2015/01/07/5http://www.openwall.com/lists/oss-security/2015/01/18/7http://www.openwall.com/lists/oss-security/2023/12/21/8http://www.openwall.com/lists/oss-security/2023/12/27/1http://www.securityfocus.com/bid/71914http://www.ubuntu.com/usn/USN-2906-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774669https://lists.gnu.org/archive/html/bug-cpio/2015-01/msg00000.htmlhttp://advisories.mageia.org/MGASA-2015-0080.htmlhttp://packetstormsecurity.com/files/169458/Zimbra-Collaboration-Suite-TAR-Path-Traversal.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:066http://www.openwall.com/lists/oss-security/2015/01/07/5http://www.openwall.com/lists/oss-security/2015/01/18/7http://www.openwall.com/lists/oss-security/2023/12/21/8http://www.openwall.com/lists/oss-security/2023/12/27/1http://www.securityfocus.com/bid/71914http://www.ubuntu.com/usn/USN-2906-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774669https://lists.gnu.org/archive/html/bug-cpio/2015-01/msg00000.html
2015-02-19
Published