Title : Debian Security Update Fixes Multiple Cpio Vulnerabilities VUPEN ID : VUPEN/ADV-2005-1991 CVE ID : CVE-2005-1111 - CVE-2005-1229
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-10-10
Technical Description
Debian has released a security patch to correct two vulnerabilities identified in Cpio. The first flaw is due to a directory traversal error when processing specially crafted cpio archives, which may be exploited by attackers to create files in arbitrary locations on the user's system. The second issue is due to a race condition which allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete. For additional information, see : VUPEN/ADV-2005-0812
Debian GNU/Linux old-stable (woody) - Upgrade to version 2.4.2-39woody2
Debian GNU/Linux stable (sarge) - Upgrade to version 2.5-1.3
Debian GNU/Linux unstable (sid) - Upgrade to version 2.6-6 References