Input validation error in cpio - CVE-2019-14866
Published: November 7, 2019
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to GNU cpio does not properly validate files when writing tar headers during tar archive creation. A local user can trick the victim into creating a tar archive out of a directory with specially crafted files. As a result the generated archive may contain files that the attacker does not have access to.
Affected software
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - TUS
openEuler
Ansible Automation Platform
cpio (Ubuntu package)
cpio (Alpine package)
cpio (Red Hat package)
app-arch/cpio
cpio
cpio-debuginfo
cpio-debugsource
cpio-help
Red Hat OpenShift Container Platform
RecoverPoint for Virtual Machines
OpenShift Virtualization
Enterprise SONiC
Data Computing Appliance (DCA)
How to mitigate CVE-2019-14866
cpio (Ubuntu package) - addressed in versions 2.11+dfsg-5ubuntu1.1, 2.12+dfsg-9ubuntu0.1, 2.12+dfsg-6ubuntu0.18.04.1, 2.12+dfsg-6ubuntu0.19.04.1
cpio (Alpine package) - update to 2.13-r0
cpio (Red Hat package) - addressed in versions 2.11-28.el7, 2.12-8.el8_2.1, 2.12-10.el8
Red Hat OpenShift Container Platform - addressed in versions 4.3.40, 4.6.54
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
app-arch/cpio - update to 2.13-r1
cpio - update to 2.13-2
cpio-debuginfo - update to 2.13-2
cpio-debugsource - update to 2.13-2
cpio-help - update to 2.13-2
Enterprise SONiC - update to 4.1.2
Data Computing Appliance (DCA) - update to 4.3.0.0
External References
Related Security Bulletins
- Information disclosure in GNU cpio
- Ubuntu update for GNU cpio
- Input validation error in cpio (Alpine package)
- Red Hat Enterprise Linux 7 update for cpio
- Red Hat Enterprise Linux 8 update for cpio
- Red Hat Enterprise Linux 8.2 update for cpio
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.6
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 1.2
- Multiple vulnerabilities in Dell EMC Enterprise SONiC
- openEuler 20.03 LTS update for cpio
- Gentoo update for cpio
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in OpenShift Virtualization 2.6
- Multiple vulnerabilities in Ansible Automation Platform 1.0 packages
- Multiple vulnerabilities in Ansible Automation Platform 1.1 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.3
- Dell RecoverPoint for Virtual Machines update for third-party components