SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-7216

A path traversal vulnerability was found in the CPIO utility.

MEDIUM 5.3EPSS 0.90%

Does this matter?

Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.

Description

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
EPSS
0.90% probability · 58th percentile
CISA KEV
Not listed
Weakness
CWE-59, CWE-22
Affected
gnu/cpio · redhat/enterprise linux
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.