bug-cpio
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

CVE-2010-4226


From: Jon Slobodzian
Subject: CVE-2010-4226
Date: Sat, 18 Jun 2022 08:37:26 +0000

Hello gnu.org,

 

I am investigating various CVE’s against the CBL-Mariner distribution.  NIST (and subsequently our tooling) suggests that this CVE is active against all versions of cpio:  https://nvd.nist.gov/vuln/detail/CVE-2010-4226.  The associated CVE description also suggests that this vulnerability only occurs by the way cpio is used, but does not list an exploit or provide any explanation suggesting what that might be.

 

I am curious as to what gnu.org’s official position is on this CVE.  Looking through the cpio changelog it does not appear to be addressed.  

 

Sincerely

Jon Slobodzian

 


reply via email to

[Prev in Thread] Current Thread [Next in Thread]