Bugzilla – Bug 1077990
VUL-1: CVE-2017-7516: cpio: --no-absolute-filenames bypass via symlinks
Last modified: 2018-03-29 14:38:15 UTC
rh#1539685 A possible --no-absolute-filenames bypass while extracting a malicious archive in cpio. This allows for arbitrary file creation. References: https://bugzilla.redhat.com/show_bug.cgi?id=1539685 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7516 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7516
http://lists.gnu.org/archive/html/bug-cpio/2017-06/msg00001.html
According to [1] this CVE seems to be a duplicate of CVE-2015-1197 which was already resolved in bug 913677. @security-team: Can we close this as invalid? [1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7516
yes, this is a duplicate. *** This bug has been marked as a duplicate of bug 913677 ***