Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: canonical
Published: 2024-01-05T00:39:49.690Z
Updated: 2025-05-07T20:19:53.516Z
Reserved: 2024-01-05T00:09:37.741Z
Link: CVE-2023-7207

Updated: 2024-08-02T08:57:35.151Z

Status : Awaiting Analysis
Published: 2024-02-29T01:42:59.920
Modified: 2025-05-07T21:16:00.603
Link: CVE-2023-7207
