CVE-2023-7216
Public on 2024-02-05
Modified on 2024-05-07
Description
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which could be utilized to run arbitrary commands on the target system.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | cpio | Pending Fix | ||
Amazon Linux 2 - Core | cpio | Pending Fix | ||
Amazon Linux 2023 | cpio | Pending Fix | ||
Amazon Linux 1 | libarchive | Not Affected | ||
Amazon Linux 2 - Core | libarchive | Not Affected | ||
Amazon Linux 2023 | libarchive | Not Affected | ||
Amazon Linux 2 - Core | python-cpio | Not Affected | ||
Amazon Linux 2 - Core | star | Not Affected | ||
Amazon Linux 2023 | star | Not Affected |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 5.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
NVD | CVSSv3 | 5.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |