Vulnerabilities > GNU > Cpio > 2.11

DATE CVE VULNERABILITY TITLE RISK
2021-08-08 CVE-2021-38185 Integer Overflow or Wraparound vulnerability in GNU Cpio
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write.
local
low complexity
gnu CWE-190
7.8
2020-01-07 CVE-2019-14866 In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives.
local
low complexity
gnu redhat
7.3
2016-02-22 CVE-2016-2037 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
network
gnu debian CWE-119
4.3
2014-12-02 CVE-2014-9112 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.
network
low complexity
gnu debian CWE-119
5.0