cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cpio | Gnu | * | * |
Opensuse | Opensuse | 2007.05.10 (including) | 2007.05.10 (including) |
Opensuse | Opensuse | 2010.07.28 (including) | 2010.07.28 (including) |