cpio 2.13+dfsg-2ubuntu0.4 source package in Ubuntu

Changelog

cpio (2.13+dfsg-2ubuntu0.4) focal-security; urgency=medium

  * SECURITY UPDATE: Path traversal vulnerability
    - debian/patches/CVE-2023-7207.patch: Create symlink placeholder
      if --no-absolute-filenames was given and replace placeholders
      after extraction.
    - debian/patches/revert-CVE-2015-1197-handling.patch: Removed.
    - CVE-2023-7207

 -- Fabian Toepfer <email address hidden>  Sun, 28 Apr 2024 14:31:25 +0200

Upload details

Uploaded by:
Fabian Toepfer
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
utils
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Focal updates main utils
Focal security main utils

Downloads

File Size SHA-256 Checksum
cpio_2.13+dfsg.orig.tar.bz2 1.3 MiB fd1e6fb3c683bf82ae0db237af87376c6a376d1f6bf6564c9b335785e76106a9
cpio_2.13+dfsg-2ubuntu0.4.debian.tar.xz 36.8 KiB c1db93be58177ec5fdf98076eb20877891de26648d262313558be442d3f85c9d
cpio_2.13+dfsg-2ubuntu0.4.dsc 2.1 KiB 9b132afcb8af58bbaab043ce99423ea3627ad3fbe48b1c03ddbece60c442fb1b

View changes file

Binary packages built by this source

cpio: GNU cpio -- a program to manage archives of files

 GNU cpio is a tool for creating and extracting archives, or copying
 files from one place to another. It handles a number of cpio formats
 as well as reading and writing tar files.

cpio-win32: GNU cpio -- a program to manage archives of files (win32 build)

 GNU cpio is a tool for creating and extracting archives, or copying
 files from one place to another. It handles a number of cpio formats
 as well as reading and writing tar files.
 .
 This is a win32 version of cpio. It's meant to be used by the win32-loader
 component of Debian-Installer.