cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.
2014-02-06T17:00:03.167
2025-06-09T15:15:22.147
Deferred
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnu | cpio | * | Yes |
Operating System | opensuse | opensuse | 2007.05.10 | Yes |
Operating System | opensuse | opensuse | 2010.07.28 | Yes |