Cpio
Vendor:
First CVE: May 2, 2005 · Active for 21 years
12
Total CVEs
More Total CVEs than 90% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cpio over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Feb 29, 2024
876 days ago
CVE Severity & Scoring
Cpio12 CVEs
17%
58%
25%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local4 (33.3%)
Network3 (25.0%)
Unknown5 (41.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (50.0%)
High1 (8.3%)
Unknown5 (41.7%)
User Interaction
None3 (25.0%)
Unknown5 (41.7%)
Required4 (33.3%)
Privileges Required
Low2 (16.7%)
High2 (16.7%)
None3 (25.0%)
Unknown5 (41.7%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-38185HIGH GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap | Aug 8, 2021 | 7.8 | 27 | NO | NO |
CVE-2010-0624MEDIUM Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to | Mar 15, 2010 | 6.8 | 25 | NO | NO |
CVE-2019-14866HIGH In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write t | Jan 7, 2020 | 7.3 | 24 | NO | NO |
CVE-2010-4226HIGH cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive. | Feb 6, 2014 | 7.2 | 24 | NO | NO |
CVE-2016-2037MEDIUM The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file. | Feb 22, 2016 | 6.5 | 23 | NO | NO |
CVE-2023-7207MEDIUM Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstre | Feb 29, 2024 | 4.9 | 17 | NO | NO |
CVE-2014-9112MEDIUM Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive. | Dec 2, 2014 | 5.0 | 17 | NO | NO |
CVE-2023-7216MEDIUM A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. Dur | Feb 5, 2024 | 5.3 | 15 | NO | NO |
CVE-2005-1229MEDIUM Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file. | May 2, 2005 | 4.6 | 15 | NO | NO |
CVE-2005-1111MEDIUM Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permission | May 2, 2005 | 4.7 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Cpio
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.9 | 1 | 6.8 | 4.8% | 0 | 0 |
| 2.8 | 1 | 6.8 | 4.8% | 0 | 0 |
| 2.7 | 1 | 6.8 | 4.8% | 0 | 0 |
| 2.6-8 | 1 | 3.7 | 0.5% | 0 | 0 |
| 2.6 | 1 | 6.8 | 4.8% | 0 | 0 |
| 2.5.90 | 1 | 6.8 | 4.8% | 0 | 0 |
| 2.5 | 1 | 6.8 | 4.8% | 0 | 0 |
| 2.4-2 | 1 | 6.8 | 4.8% | 0 | 0 |
| 2.13 | 1 | 4.9 | 0.9% | 0 | 0 |
| 2.11 | 3 | 4.5 | 5.2% | 0 | 0 |
| 1.3 | 1 | 6.8 | 4.8% | 0 | 0 |
| 1.2 | 1 | 6.8 | 4.8% | 0 | 0 |
| 1.1 | 1 | 6.8 | 4.8% | 0 | 0 |
| 1.0 | 1 | 6.8 | 4.8% | 0 | 0 |