Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: canonical
Published: 2024-01-05T00:39:49.690Z
Updated: 2025-02-13T17:27:05.205Z
Reserved: 2024-01-05T00:09:37.741Z
Link: CVE-2023-7207

Updated: 2024-08-02T08:57:35.151Z

Status : Awaiting Analysis
Published: 2024-02-29T01:42:59.920
Modified: 2024-11-21T08:45:30.623
Link: CVE-2023-7207
