#VU22598 Input validation error in cpio - CVE-2019-14866
Published: November 7, 2019
cpio
GNU
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to GNU cpio does not properly validate files when writing tar headers during tar archive creation. A local user can trick the victim into creating a tar archive out of a directory with specially crafted files. As a result the generated archive may contain files that the attacker does not have access to.