cpio 安全漏洞

admin 2024-01-13 22:12:07 YS 来源:ZONE.CI 全球网 0 阅读模式
> cpio 安全漏洞

cpio 安全漏洞

CNNVD-ID编号 CNNVD-201911-244 CVE编号 CVE-2019-14866
发布时间 2019-11-06 更新时间 2021-02-04
漏洞类型 其他 漏洞来源 N/A
危险等级 高危 威胁类型 本地
厂商 N/A

漏洞介绍

cpio是一款用于类UNIX系统的文件备份程序。

cpio 2.13之前版本中存在安全漏洞,该漏洞源于程序生成TAR归档文件时没有正确验证输入的文件。攻击者可利用该漏洞提升权限,入侵系统。

漏洞补丁

目前厂商已发布升级了cpio 安全漏洞的补丁,cpio 安全漏洞的补丁获取链接:

参考网址

来源:lists.gnu.org

链接:https://lists.gnu.org/archive/html/bug-cpio/2019-11/msg00000.html

来源:bugzilla.redhat.com

链接:https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14866

来源:lists.gnu.org

链接:https://lists.gnu.org/archive/html/bug-cpio/2019-08/msg00003.html

来源:security-tracker.debian.org

链接:https://security-tracker.debian.org/tracker/DLA-1981-1

来源:www.suse.com

链接:https://www.suse.com/support/update/announcement/2019/suse-su-20193064-1.html

来源:usn.ubuntu.com

链接:https://usn.ubuntu.com/4176-1/

来源:www.vuxml.org

链接:http://www.vuxml.org/freebsd/f59af308-07f3-11ea-8c56-f8b156b6dcc8.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.3535/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/159553/Red-Hat-Security-Advisory-2020-4255-01.html

来源:nvd.nist.gov

链接:https://nvd.nist.gov/vuln/detail/CVE-2019-14866

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/159393/Red-Hat-Security-Advisory-2020-3908-01.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.4171/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.4094/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-siem-is-vulnerable-to-using-components-with-known-vulnerabilities-6/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2021.0319/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-siem-is-vulnerable-to-using-components-with-known-vulnerabilities-4/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.4360/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.4470/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/159661/Red-Hat-Security-Advisory-2020-4264-01.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2021.0386/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/155191/Ubuntu-Security-Notice-USN-4176-1.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.3631/

来源:vigilance.fr

链接:https://vigilance.fr/vulnerability/cpio-file-creation-via-Restore-30787

受影响实体

暂无

信息来源

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201911-244

weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论:0   参与:  0