UBUNTU-CVE-2021-38185
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-38185
UBUNTU-CVE-2021-38185
Summary:
Details: GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.
References: https://ubuntu.com/security/CVE-2021-38185, https://github.com/fangqyi/cpiopwn, https://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00000.html, https://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00002.html, https://ubuntu.com/security/notices/USN-5064-1, https://ubuntu.com/security/notices/USN-5064-2, https://ubuntu.com/security/notices/USN-5064-3, https://www.cve.org/CVERecord?id=CVE-2021-38185
Affected packages
Package
Name: cpio
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu1.2+esm2?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
