CVE-2016-2037
published 2016-02-22CVE-2016-2037: The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
PriorityP432medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
5.48%
91.9th percentile
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cpio | < cpio 2.11+dfsg-5 (bookworm) | cpio 2.11+dfsg-5 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| gnu | cpio | — | — |
| gnu | cpio | >= 0 < 2.11+dfsg-5 | 2.11+dfsg-5 |
| gnu | cpio | >= 0 < 2.11+dfsg-5 | 2.11+dfsg-5 |
| gnu | cpio | >= 0 < 2.11+dfsg-5 | 2.11+dfsg-5 |
| gnu | cpio | >= 0 < 2.11+dfsg-5 | 2.11+dfsg-5 |
| gnu | cpio | >= 0 < 2.11+dfsg-1ubuntu1.2 | 2.11+dfsg-1ubuntu1.2 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU cpio vulnerabilities
vendor_ubuntu·2016-02-22·CVSS 1.9
CVE-2015-1197 [LOW] GNU cpio vulnerabilities
Title: GNU cpio vulnerabilities
Summary: Several security issues were fixed in GNU cpio.
Alexander Cherepanov discovered that GNU cpio incorrectly handled symbolic
links when used with the --no-absolute-filenames option. If a user or
automated system were tricked into extracting a specially-crafted cpio
archive, a remote attacker could possibly use this issue to write arbitrary
files. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2015-1197)
Gustavo Grieco discovered that GNU cpio incorrectly handled memory when
extracting archive files. If a user or automated system were tricked into
extracting a specially-crafted cpio archive, a remote attacker could use
this issue to cause GNU cpio to crash, resulting in a denial of service, or
possibly execute arbitrary code. (
Red Hat
cpio: out of bounds write
vendor_redhat·2016-01-19·CVSS 6.5
CVE-2016-2037 [MEDIUM] CWE-787 cpio: out of bounds write
cpio: out of bounds write
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
Package: cpio (Red Hat Enterprise Linux 5) - Will not fix
Package: cpio (Red Hat Enterprise Linux 6) - Will not fix
Package: cpio (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-2037: cpio - The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attacke...
vendor_debian·2016·CVSS 6.5
CVE-2016-2037 [MEDIUM] CVE-2016-2037: cpio - The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attacke...
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
Scope: local
bookworm: resolved (fixed in 2.11+dfsg-5)
bullseye: resolved (fixed in 2.11+dfsg-5)
forky: resolved (fixed in 2.11+dfsg-5)
sid: resolved (fixed in 2.11+dfsg-5)
trixie: resolved (fixed in 2.11+dfsg-5)
GHSA
GHSA-g3qq-8w29-572m: The cpio_safer_name_suffix function in util
ghsa_unreviewed·2022-05-17
CVE-2016-2037 [MEDIUM] CWE-119 GHSA-g3qq-8w29-572m: The cpio_safer_name_suffix function in util
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
OSV
cpio vulnerabilities
osv·2016-02-22·CVSS 1.9
CVE-2015-1197 [LOW] cpio vulnerabilities
cpio vulnerabilities
Alexander Cherepanov discovered that GNU cpio incorrectly handled symbolic
links when used with the --no-absolute-filenames option. If a user or
automated system were tricked into extracting a specially-crafted cpio
archive, a remote attacker could possibly use this issue to write arbitrary
files. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2015-1197)
Gustavo Grieco discovered that GNU cpio incorrectly handled memory when
extracting archive files. If a user or automated system were tricked into
extracting a specially-crafted cpio archive, a remote attacker could use
this issue to cause GNU cpio to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2016-2037)
OSV
CVE-2016-2037: The cpio_safer_name_suffix function in util
osv·2016-02-22·CVSS 6.5
CVE-2016-2037 [MEDIUM] CVE-2016-2037: The cpio_safer_name_suffix function in util
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2037 cpio: out of bounds write
bugzilla·2016-01-20·CVSS 6.5
CVE-2016-2037 [MEDIUM] CVE-2016-2037 cpio: out of bounds write
CVE-2016-2037 cpio: out of bounds write
An out of bounds write was found in a way cpio parses certain cpio files. A specially crafted file can cause the application to crash.
Original bug report with reproducer:
http://seclists.org/oss-sec/2016/q1/136
Discussion:
Created cpio tracking bugs for this issue:
Affects: fedora-all [bug 1300208]
---
Upstream fix:
https://lists.gnu.org/archive/html/bug-cpio/2016-01/msg00005.html
---
may I ask why this issue was closed as "WONTFIX"?
The cpio version in Fedora 22 and RHEL 7 are affected and are not patched.
According to LWN (lwn.net/Vulnerabilities/675700/), the issue is an out-of-bounds-write.
cpio might be invoked by amavisd-new email content scanner.
---
alright, so there's a tracking bug for Fedora. Mea culpa.
Still RHEL seems a
Bugzilla
CVE-2016-2037 cpio: out of bounds write [fedora-all]
bugzilla·2016-01-20·CVSS 6.5
CVE-2016-2037 [MEDIUM] CVE-2016-2037 cpio: out of bounds write [fedora-all]
CVE-2016-2037 cpio: out of bounds write [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one tr
http://www.debian.org/security/2016/dsa-3483http://www.openwall.com/lists/oss-security/2016/01/19/4http://www.openwall.com/lists/oss-security/2016/01/22/4http://www.securityfocus.com/bid/82293http://www.securitytracker.com/id/1035067http://www.ubuntu.com/usn/USN-2906-1http://www.debian.org/security/2016/dsa-3483http://www.openwall.com/lists/oss-security/2016/01/19/4http://www.openwall.com/lists/oss-security/2016/01/22/4http://www.securityfocus.com/bid/82293http://www.securitytracker.com/id/1035067http://www.ubuntu.com/usn/USN-2906-1
2016-02-22
Published