Title : Turbolinux Security Update Fixes Multiple Cpio Vulnerabilities VUPEN ID : VUPEN/ADV-2005-1227 CVE ID : CVE-2005-1111 - CVE-2005-1229 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2005-07-27
Technical Description
Turbolinux has released a security patch to correct two vulnerabilities identified in Cpio. The first flaw is due to a directory traversal error when processing specially crafted cpio archives, which may be exploited by attackers to create files in arbitrary locations on the user's system. The second issue is due to a race condition which allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete. For additional information, see : VUPEN/ADV-2005-0812