|
|
Log in / Subscribe / Register

Debian alert DLA-1981-1 (cpio)

From:  Ola Lundqvist <ola@inguza.com>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 1981-1] cpio security update
Date:  Tue, 5 Nov 2019 19:06:14 +0100
Message-ID:  <20191105180614.mci7746xzyfsjf5u@inguza.net>

Package : cpio Version : 2.11+dfsg-4.1+deb8u2 CVE ID : CVE-2019-14866 Debian Bug : #941412 A vulnerability was discovered in the cpio package. CVE-2019-14866 It is possible for an attacker to create a file so when backed up with cpio can generate arbitrary files in the resulting tar archive. When the backup is restored the file is then created with arbitrary permissions. For Debian 8 "Jessie", this problem has been fixed in version 2.11+dfsg-4.1+deb8u2. We recommend that you upgrade your cpio packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds