CVE-2023-7207
published 2024-02-29CVE-2023-7207: Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in…
PriorityP424medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.91%
55.8th percentile
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cpio | < cpio 2.14+dfsg-1 (forky) | cpio 2.14+dfsg-1 (forky) |
| gnu | cpio | — | — |
| gnu | cpio | >= 0 < 2.14+dfsg-1 | 2.14+dfsg-1 |
| gnu | cpio | >= 0 < 2.14+dfsg-1 | 2.14+dfsg-1 |
| msrc | cbl2_cpio_2.13-5_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
osv1.9LOW
vendor_msrc4.9MEDIUM
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x4gq-xcr8-xwp7: Debian's cpio contains a path traversal vulnerability
ghsa_unreviewed·2024-02-29·CVSS 1.9
CVE-2023-7207 [LOW] CWE-22 GHSA-x4gq-xcr8-xwp7: Debian's cpio contains a path traversal vulnerability
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
OSV
CVE-2023-7207: Debian's cpio contains a path traversal vulnerability
osv·2024-02-29·CVSS 1.9
CVE-2023-7207 [LOW] CVE-2023-7207: Debian's cpio contains a path traversal vulnerability
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
Ubuntu
GNU cpio vulnerabilities
vendor_ubuntu·2024-04-29
CVE-2023-7207 GNU cpio vulnerabilities
Title: GNU cpio vulnerabilities
Summary: GNU cpio could be made to write files outside the target directory.
Ingo Brückl discovered that cpio contained a path traversal vulnerability.
If a user or automated system were tricked into extracting a specially
crafted cpio archive, an attacker could possibly use this issue to write
arbitrary files outside the target directory on the host, even if using the
option --no-absolute-filenames.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provide
vendor_msrc·2024-01-09·CVSS 4.9
CVE-2023-7207 [LOW] CWE-22 Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provide
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional
Red Hat
cpio: path traversal vulnerability
vendor_redhat·2024-01-04·CVSS 1.9
CVE-2023-7207 [LOW] CWE-22 cpio: path traversal vulnerability
cpio: path traversal vulnerability
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
A flaw was found in cpio. The fix for CVE-2015-1197 created other issues, and the patch to fix this issue was reverted, causing a regression when the --no-absolute-filenames command line option is used, resulting in a path traversal vulnerability.
Mitigation: Do not process untrusted archives with the cpio program.
Package: cpio (Red Hat Enterprise Linux 6) - Out of support scope
Package: cpio (Red Hat Enterprise Linux 7) - Out of support scope
Package: cpio (Red Hat Enterprise Linux 8) - Will not fix
Package:
Debian
CVE-2023-7207: cpio - Debian's cpio contains a path traversal vulnerability. This issue was introduced...
vendor_debian·2023·CVSS 1.9
CVE-2023-7207 [LOW] CVE-2023-7207: cpio - Debian's cpio contains a path traversal vulnerability. This issue was introduced...
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.14+dfsg-1)
sid: resolved (fixed in 2.14+dfsg-1)
trixie: resolved (fixed in 2.14+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2024/01/05/1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1059163https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7207https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=376d663340a9dc91c91a5849e5713f07571c1628https://www.openwall.com/lists/oss-security/2023/12/21/8http://www.openwall.com/lists/oss-security/2024/01/05/1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1059163https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7207https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=376d663340a9dc91c91a5849e5713f07571c1628https://www.openwall.com/lists/oss-security/2023/12/21/8
2024-02-29
Published