cpio is vulnerable to a absolut-path issue which allows to unpack the content to any location.
Created attachment 57389 [details, diff] cpio-2.6-alt-safer_name_suffix.patch Proposed patch by Dmitry V. Levin from altlinux.org
anyone know if cpio gnu maintainers have been notified ? the fix isnt in their upstream CVS also, i dont think we need to keep this locked down ... redhat has added the patch to their public CVS ...
cpio-2.6-r3 now in portage with the redhat fix
Thx SpanKY. Arches please test and mark stable.
stable on amd64
sparc stable.
ppc64 stable
x86 stable
Stable on ppc.
Stable on hppa.
Stable on ppc-macos.
Stable on alpha + ia64.
arm/s390 stable
SpanKY thx for fixing CAN-2005-1111 (The TOCTOU issue) reference from the URL above. But as far as I understand it these are two different problems.
heh, yes they are i'll make another cpio but for the correct bug this time ;)
SpanKY do we have a fix in CVS for this one yet?
e-mailed upstream to see what they want to do
https://savannah.gnu.org/patch/?func=detailitem&item_id=4005 https://savannah.gnu.org/patch/?func=detailitem&item_id=4006 https://savannah.gnu.org/patch/?func=detailitem&item_id=4007
SpanKY anything new on this one?
SpanKY still no news?
sorry for the delay, my cvs checkout of upstream cpio was all screwed up so i was trying to wait for them :/ cpio-2.6-r4 now in portage with fix
Arches please test and mark stable. Note: If anyone is on m68k, please create an arch alias.
stable on ppc64
alpha stable
ia64 stable.
arm/s390/x86 stable
GLSA 200506-16, thanks everyone!
mips stable.