Oval Definition:oval:com.redhat.rhsa:def:20050378
Revision Date:2005-07-21Version:502
Title:RHSA-2005:378: cpio security update (Low)
Description:GNU cpio copies files into or out of a cpio or tar archive.

A race condition bug was found in cpio. It is possible for a local malicious user to modify the permissions of a local file if they have write access to a directory in which a cpio archive is being extracted. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-1111 to this issue.

Additionally, this update adds cpio support for archives larger than 2GB. However, the size of individual files within an archive is limited to 4GB.

All users of cpio are advised to upgrade to this updated package, which contains backported fixes for these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2005-1111
RHSA-2005:378-01
Platform(s):Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND cpio is earlier than 0:2.5-4.RHEL3
  • AND cpio is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND cpio is earlier than 0:2.5-8.RHEL4
  • AND cpio is signed with Red Hat master key
  • BACK