CVE-2019-14866
published 2020-01-07CVE-2019-14866: In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an…
PriorityP335high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.69%
48.5th percentile
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cpio | < cpio 2.13+dfsg-1 (bookworm) | cpio 2.13+dfsg-1 (bookworm) |
| gnu | cpio | < 2.13 | 2.13 |
| gnu | cpio | >= 0 < 2.13+dfsg-1 | 2.13+dfsg-1 |
| gnu | cpio | >= 0 < 2.13+dfsg-1 | 2.13+dfsg-1 |
| gnu | cpio | >= 0 < 2.13+dfsg-1 | 2.13+dfsg-1 |
| gnu | cpio | >= 0 < 2.13+dfsg-1 | 2.13+dfsg-1 |
| red_hat | cpio | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.3HIGH
vendor_debian7.3LOW
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU cpio vulnerability
vendor_ubuntu·2019-11-06
CVE-2019-14866 GNU cpio vulnerability
Title: GNU cpio vulnerability
Summary: GNU cpio could be used to privilege escalation if it received
a specially crafted input.
Thomas Habets discovered that GNU cpio incorrectly handled certain inputs.
An attacker could possibly use this issue to privilege escalation.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cpio: improper input validation when writing tar header fields leads to unexpected tar generation
vendor_redhat·2019-08-30·CVSS 7.3
CVE-2019-14866 [HIGH] CWE-20 cpio: improper input validation when writing tar header fields leads to unexpected tar generation
cpio: improper input validation when writing tar header fields leads to unexpected tar generation
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.
It was discovered cpio does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he
Debian
CVE-2019-14866: cpio - In all versions of cpio before 2.13 does not properly validate input files when ...
vendor_debian·2019·CVSS 7.3
CVE-2019-14866 [HIGH] CVE-2019-14866: cpio - In all versions of cpio before 2.13 does not properly validate input files when ...
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.
Scope: local
bookworm: resolved (fixed in 2.13+dfsg-1)
bullseye: resolved (fixed in 2.13+dfsg-1)
forky: resolved (fixed in 2.13+dfsg-1)
sid: resolved (fixed in 2.13+dfsg-1)
trixie: resolved (fixed in 2.13+dfsg-1)
GHSA
GHSA-g3pr-277r-xcx7: In all versions of cpio before 2
ghsa_unreviewed·2022-05-24
CVE-2019-14866 [MEDIUM] CWE-20 GHSA-g3pr-277r-xcx7: In all versions of cpio before 2
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.
OSV
CVE-2019-14866: In all versions of cpio before 2
osv·2020-01-07·CVSS 7.3
CVE-2019-14866 [HIGH] CVE-2019-14866: In all versions of cpio before 2
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14866 cpio: improper input validation when writing tar header fields leads to unexpect tar generation [fedora-all]
bugzilla·2019-10-28·CVSS 7.3
CVE-2019-14866 [HIGH] CVE-2019-14866 cpio: improper input validation when writing tar header fields leads to unexpect tar generation [fedora-all]
CVE-2019-14866 cpio: improper input validation when writing tar header fields leads to unexpect tar generation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2019-14866 cpio: improper input validation when writing tar header fields leads to unexpected tar generation
bugzilla·2019-10-25·CVSS 7.3
CVE-2019-14866 [HIGH] CVE-2019-14866 cpio: improper input validation when writing tar header fields leads to unexpected tar generation
CVE-2019-14866 cpio: improper input validation when writing tar header fields leads to unexpected tar generation
cpio does not properly validate the values written in the header of a TAR file through the to_oct() function. When creating a TAR file from a list of files and one of those is another TAR file with a big size, cpio will generate the resulting file with the content extracted from the input one. This leads to unexpected results as the newly generated TAR file could have files with permissions the owner of the input TAR file did not have or in paths he did not have access to.
References:
https://lists.gnu.org/archive/html/bug-cpio/2019-08/msg00003.html
Proposed patch:
https://cement.retrofitta.se/tmp/cpio-tar.patch
Discussion:
Mitigation:
TAR archives should be inspected befo
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14866https://lists.debian.org/debian-lts-announce/2023/06/msg00007.htmlhttps://lists.gnu.org/archive/html/bug-cpio/2019-08/msg00003.htmlhttps://lists.gnu.org/archive/html/bug-cpio/2019-11/msg00000.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14866https://lists.debian.org/debian-lts-announce/2023/06/msg00007.htmlhttps://lists.gnu.org/archive/html/bug-cpio/2019-08/msg00003.htmlhttps://lists.gnu.org/archive/html/bug-cpio/2019-11/msg00000.html
2020-01-07
Published