Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cpio | Gnu | * | 2.6 (including) |
Red Hat Enterprise Linux 3 | RedHat | cpio-0:2.5-4.RHEL3 | * |
Red Hat Enterprise Linux 4 | RedHat | cpio-0:2.5-8.RHEL4 | * |
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | RedHat | * | |
Red Hat Enterprise Linux ES version 2.1 | RedHat | * | |
Red Hat Enterprise Linux WS version 2.1 | RedHat | * | |
Red Hat Linux Advanced Workstation 2.1 | RedHat | * | |
Cpio | Ubuntu | dapper | * |
Cpio | Ubuntu | devel | * |
Cpio | Ubuntu | edgy | * |
Cpio | Ubuntu | feisty | * |