漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Path Traversal in GNU cpio
Vulnerability Description
GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the link_to_name function without equivalent sanitization before calling link function. A tar archive provided by an attacker, containing a hard-link entry whose linkname is set to an absolute path outside the extraction directory, can cause cpio to create a hard link to an existing file outside the intended extraction directory, breaking the expected guarantee of --no-absolute-filenames and allowing archive-controlled linkage to external files.
This issue has been fixed in commit e2b9cbdd3354d2b1569b7390d1bc15c1930559ad
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
GNU cpio 路径遍历漏洞
Vulnerability Description
GNU cpio是美国GNU基金会开源的一款文件归档与提取工具。 GNU cpio 2.15及之前版本存在路径遍历漏洞,该漏洞源于提取tar归档时,使用--no-absolute-filenames选项处理硬链接目标路径时未进行充分清理,可能允许攻击者创建指向提取目录外部文件的硬链接。
CVSS Information
N/A
Vulnerability Type
N/A