Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Aug 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gnu
Gnu cpio |
|
CPEs | cpe:2.3:a:gnu:cpio:2.13:*:*:*:*:*:*:* | |
Vendors & Products |
Gnu
Gnu cpio |
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Thu, 13 Feb 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: canonical
Published: 2024-01-05T00:39:49.690Z
Updated: 2025-05-07T20:19:53.516Z
Reserved: 2024-01-05T00:09:37.741Z
Link: CVE-2023-7207

Updated: 2024-08-02T08:57:35.151Z

Status : Analyzed
Published: 2024-02-29T01:42:59.920
Modified: 2025-08-26T17:19:09.897
Link: CVE-2023-7207
