NASLDB: RHSA-2005-378: cpio
General
ID: 19283
Name: RHSA-2005-378: cpio
Summary: Check for the version of the cpio packages
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: CVSS2#AV:L/AC:H/Au:N/C:P/I:P/A:P
CVSS Base Vector: –
CVSS Temporal Vector: –
Port: 0
Family: Red Hat Local Security Checks
Type: Local
Description
An updated cpio package that fixes multiple issues is now available.
This update has been rated as having low security impact by the Red Hat
Security Response Team.
GNU cpio copies files into or out of a cpio or tar archive.
A race condition bug was found in cpio. It is possible for a local
malicious user to modify the permissions of a local file if they have write
access to a directory in which a cpio archive is being extracted. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1111 to this issue.
Additionally, this update adds cpio support for archives larger than 2GB.
However, the size of individual files within an archive is limited to 4GB.
All users of cpio are advised to upgrade to this updated package, which
contains backported fixes for these issues.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2005-1111
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: –
Plugin Release: 2005/07/22
Plugin
Version: 1.10
Filename: redhat-RHSA-2005-378.nasl
Filesize: 2634 bytes
MD5 Hash: 01ee19a42b6f33122f2c42e164d8b4a4
Identification: Host/RedHat/rpm-list
Require Keys: Host/RedHat/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2005-2011 Tenable Network Security, Inc.
- Letzte Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













