Bug 1077990 (CVE-2017-7516) - VUL-1: CVE-2017-7516: cpio: --no-absolute-filenames bypass via symlinks
Summary: VUL-1: CVE-2017-7516: cpio: --no-absolute-filenames bypass via symlinks
Status: RESOLVED DUPLICATE of bug 913677
Alias: CVE-2017-7516
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Kristyna Streitova
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/199114/
Whiteboard: CVSSv3:RedHat:CVE-2017-7516:4.4:(AV:L...
Keywords:
Depends on:
Blocks:
 
Reported: 2018-01-29 13:05 UTC by Marcus Meissner
Modified: 2018-03-29 14:38 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2018-01-29 13:05:35 UTC
rh#1539685

A possible --no-absolute-filenames bypass while extracting a malicious archive in cpio. This allows for arbitrary file creation.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1539685
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7516
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7516
Comment 2 Kristyna Streitova 2018-03-29 09:57:22 UTC
According to [1] this CVE seems to be a duplicate of CVE-2015-1197 which was already resolved in bug 913677.

@security-team: Can we close this as invalid? 


[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7516
Comment 3 Marcus Meissner 2018-03-29 11:15:25 UTC
yes, this is a duplicate.

*** This bug has been marked as a duplicate of bug 913677 ***