Input validation error in cpio - CVE-2019-14866

 

Input validation error in cpio - CVE-2019-14866

Published: November 7, 2019


Vulnerability identifier: #VU22598
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14866
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to GNU cpio does not properly validate files when writing tar headers during tar archive creation. A local user can trick the victim into creating a tar archive out of a directory with specially crafted files. As a result the generated archive may contain files that the attacker does not have access to.


Affected software

cpio
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - TUS
openEuler
Ansible Automation Platform
cpio (Ubuntu package)
cpio (Alpine package)
cpio (Red Hat package)
app-arch/cpio
cpio
cpio-debuginfo
cpio-debugsource
cpio-help
Red Hat OpenShift Container Platform
RecoverPoint for Virtual Machines
OpenShift Virtualization
Enterprise SONiC
Data Computing Appliance (DCA)

How to mitigate CVE-2019-14866

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
cpio (Ubuntu package) - addressed in versions 2.11+dfsg-5ubuntu1.1, 2.12+dfsg-9ubuntu0.1, 2.12+dfsg-6ubuntu0.18.04.1, 2.12+dfsg-6ubuntu0.19.04.1
cpio (Alpine package) - update to 2.13-r0
cpio (Red Hat package) - addressed in versions 2.11-28.el7, 2.12-8.el8_2.1, 2.12-10.el8
Red Hat OpenShift Container Platform - addressed in versions 4.3.40, 4.6.54
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
app-arch/cpio - update to 2.13-r1
cpio - update to 2.13-2
cpio-debuginfo - update to 2.13-2
cpio-debugsource - update to 2.13-2
cpio-help - update to 2.13-2
Enterprise SONiC - update to 4.1.2
Data Computing Appliance (DCA) - update to 4.3.0.0

External References

Related Security Bulletins