Title : Ubuntu Security Update Fixes cpio Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-2729 CVE ID : CVE-2007-4476
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-10-06
Technical Description
A vulnerability has been identified in Ubuntu, which could be exploited by attackers to execute arbitrary code. This issue is caused by an error in cpio. For additional information, see : VUPEN/ADV-2007-3511
Ubuntu 6.06 LTS - Upgrade to cpio version 2.6-10ubuntu0.3
Ubuntu 7.04 - Upgrade to cpio version 2.6-17ubuntu0.7.04.1
Ubuntu 7.10 - Upgrade to cpio version 2.8-1ubuntu2.2 References