cbcvebase.
CVE-2019-14866
published 2020-01-07

CVE-2019-14866: In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an…

PriorityP335high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.69%
48.5th percentile
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiancpio< cpio 2.13+dfsg-1 (bookworm)cpio 2.13+dfsg-1 (bookworm)
gnucpio< 2.132.13
gnucpio>= 0 < 2.13+dfsg-12.13+dfsg-1
gnucpio>= 0 < 2.13+dfsg-12.13+dfsg-1
gnucpio>= 0 < 2.13+dfsg-12.13+dfsg-1
gnucpio>= 0 < 2.13+dfsg-12.13+dfsg-1
red_hatcpio
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.3HIGH
vendor_debian7.3LOW
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.