#VU22598 Input validation error in cpio - CVE-2019-14866

 

#VU22598 Input validation error in cpio - CVE-2019-14866

Published: November 7, 2019


Vulnerability identifier: #VU22598
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-14866
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
cpio
Software vendor:
GNU

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to GNU cpio does not properly validate files when writing tar headers during tar archive creation. A local user can trick the victim into creating a tar archive out of a directory with specially crafted files. As a result the generated archive may contain files that the attacker does not have access to.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links