CVE-2015-1197 describes a symlink attack vulnerability in GNU cpio version 2.11 when using the --no-absolute-filenames option, allowing local users to write to arbitrary files. This vulnerability has a low CVSS score of 1.9, indicating a local attack vector, medium attack complexity, and a potential impact limited to partial integrity. While there is no known exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion and media coverage, though it is not listed on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.11CPE matchmatch criteria | cpe:2.3:a:gnu:cpio:2.11:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.