VulnerabilityAnalyzed
CVE-2023-7207
Debian's cpio contains a path traversal vulnerability.
MEDIUM 4.9EPSS 0.91%
Does this matter?
Lower severity and a low EPSS score (0.91%). Track it; it rarely justifies an emergency change on its own.
Description
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- gnu/cpio
- Source
- security@ubuntu.com
References
- http://www.openwall.com/lists/oss-security/2024/01/05/1Mailing List
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1059163Issue Tracking
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7207Third Party Advisory
- https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=376d663340a9dc91c91a5849e5713f07571c1628Mailing List, Patch
- https://www.openwall.com/lists/oss-security/2023/12/21/8Mailing List
- http://www.openwall.com/lists/oss-security/2024/01/05/1Mailing List
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1059163Issue Tracking
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7207Third Party Advisory
- https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=376d663340a9dc91c91a5849e5713f07571c1628Mailing List, Patch
- https://www.openwall.com/lists/oss-security/2023/12/21/8Mailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.