Bug 1077990 (CVE-2017-7516)

Summary: VUL-1: CVE-2017-7516: cpio: --no-absolute-filenames bypass via symlinks
Product: [Novell Products] SUSE Security Incidents Reporter: Marcus Meissner <meissner>
Component: IncidentsAssignee: Kristyna Streitova <kstreitova>
Status: RESOLVED DUPLICATE QA Contact: Security Team bot <security-team>
Severity: Minor    
Priority: P4 - Low CC: security-team, smash_bz
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/199114/
Whiteboard: CVSSv3:RedHat:CVE-2017-7516:4.4:(AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L) CVSSv3:SUSE:CVE-2017-7516:4.4:(AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Marcus Meissner 2018-01-29 13:05:35 UTC
rh#1539685

A possible --no-absolute-filenames bypass while extracting a malicious archive in cpio. This allows for arbitrary file creation.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1539685
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7516
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7516
Comment 2 Kristyna Streitova 2018-03-29 09:57:22 UTC
According to [1] this CVE seems to be a duplicate of CVE-2015-1197 which was already resolved in bug 913677.

@security-team: Can we close this as invalid? 


[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7516
Comment 3 Marcus Meissner 2018-03-29 11:15:25 UTC
yes, this is a duplicate.

*** This bug has been marked as a duplicate of bug 913677 ***