A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.
History

Thu, 19 Sep 2024 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2024-02-05T15:12:17.193Z

Updated: 2024-09-19T05:45:38.890Z

Reserved: 2024-01-05T14:21:24.756Z

Link: CVE-2023-7216

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2024-02-05T15:15:08.903

Modified: 2024-09-19T06:15:02.437

Link: CVE-2023-7216

cve-icon Redhat

Severity : Low

Publid Date: 2024-02-05T00:00:00Z

Links: CVE-2023-7216 - Bugzilla