Title : Gentoo Security Update Fixes Cpio Directory Traversal Vulnerability VUPEN ID : VUPEN/ADV-2005-0812 CVE ID : CVE-2005-1111 CWE ID : CWE-
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-06-20
Technical Description
Gentoo has released a security patch to correct a vulnerability identified in Cpio. This flaw is due to a directory traversal error when processing specially crafted cpio archives, which may be exploited by attackers to create files in arbitrary locations on the user's system.