NA

CVE-2023-7216

Published: 05/02/2024 Updated: 26/03/2024
CVSS v3 Base Score: 5.3 | Impact Score: 3.4 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated malicious user to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, this allows writing files in arbitrary directories through symlinks.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu cpio -

redhat enterprise linux 7.0

redhat enterprise linux 8.0

redhat enterprise linux 9.0

Vendor Advisories

Description<!---->A path traversal vulnerability was found in the CPIO utility This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive During the extraction process, the archiver could follow symlinks outside of the intended directory, which could be utilized to run arbitrary commands on t ...