USN-2456-1

    Dashboard / Vulnerabilities / USN-2456-1

    USN-2456-1

    Published: 8 Jan 2015Last Modified: 10 Feb 2026

    Summary: cpio vulnerabilities

    Details: Michal Zalewski discovered an out of bounds write issue in the process_copy_in function of GNU cpio. An attacker could specially craft a cpio archive that could create a denial of service or possibly execute arbitrary code. (CVE-2014-9112) Jakob Lell discovered a heap-based buffer overflow in the rmt_read__ function of GNU cpio's rmt client functionality. An attacker controlling a remote rmt server could use this to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 10.04 LTS. (CVE-2010-0624)

    Affected packages

    Package

    Name: cpio

    Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu1.1?arch=source&distro=trusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.11+dfsg-1ubuntu1.1

    Affected versions

    2.11+dfsg-1ubuntu1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High