Total vulnerabilities in the database
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
Software | From | Fixed in |
---|---|---|
gnu / cpio | - | 2.6.x |
debian / debian_linux | 3.1 | 3.1.x |
debian / debian_linux | 3.0 | 3.0.x |
canonical / ubuntu_linux | 4.10 | 4.10.x |
canonical / ubuntu_linux | 5.04 | 5.04.x |