CVE-1999-1572 Affecting cpio package, versions <2.5-1.2


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.05% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN9-CPIO-297888
  • published16 Jul 1996
  • disclosed16 Jul 1996

Introduced: 16 Jul 1996

CVE-1999-1572  (opens in a new tab)

How to fix?

Upgrade Debian:9 cpio to version 2.5-1.2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream cpio package and not the cpio package as distributed by Debian. See How to fix? for Debian:9 relevant fixed versions and status.

cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.

CVSS Scores

version 3.1