Oval Definition:oval:com.redhat.rhsa:def:20100145
Revision Date:2010-03-15Version:634
Title:RHSA-2010:0145: cpio security update (Moderate)
Description:GNU cpio copies files into or out of a cpio or tar archive.

  • A heap-based buffer overflow flaw was found in the way cpio expanded archive files. If a user were tricked into expanding a specially-crafted archive, it could cause the cpio executable to crash or execute arbitrary code with the privileges of the user running cpio. (CVE-2010-0624)

    Red Hat would like to thank Jakob Lell for responsibly reporting the CVE-2010-0624 issue.

  • A stack-based buffer overflow flaw was found in the way cpio expanded large archive files. If a user expanded a specially-crafted archive, it could cause the cpio executable to crash. This issue only affected 64-bit platforms. (CVE-2005-4268)

    Users of cpio are advised to upgrade to this updated package, which contains backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2005-4268
    CVE-2010-0624
    RHSA-2010:0145
    RHSA-2010:0145-01
    RHSA-2010:0145-01
    Platform(s):Red Hat Enterprise Linux 3
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND cpio is earlier than 0:2.5-6.RHEL3
  • AND cpio is signed with Red Hat master key
  • BACK