Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Fri, 16 Jan 2015 05:44:25 +0300
From: Alexander Cherepanov <ch3root@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: CVE Request: cpio -- directory traversal

Hi!

cpio is susceptible to a directory traversal vulnerability via symlinks.

Initial report:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774669

Upstream report:
https://lists.gnu.org/archive/html/bug-cpio/2015-01/msg00000.html

Some discussion:
http://www.openwall.com/lists/oss-security/2015/01/07/5
http://www.openwall.com/lists/oss-security/2015/01/08/4

Could CVE(s) please be assigned?

-- 
Alexander Cherepanov

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.