Secunia - Stay Secure
Gartner
Home Corporate Website Jobs Updated Mailing Lists RSS Blog  Online Shop Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


Fedora update for cpio Advisory Available in Danish  Advisory Available in German 

Secunia Advisory: SA27476  
Release Date: 2007-11-06

Critical:
Not critical
Impact: DoS
Where: From remote
Solution Status: Vendor Patch

OS:Fedora 7
Fedora Core 6


CVE reference:CVE-2007-4476 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
Fedora has issued an update for cpio. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error when processing specially crafted tar archives and can be exploited to cause a stack-based buffer overflow and crash the vulnerable application.

Solution:
Apply updated packages.

Fedora Core 6:

1971c968ff5f31b382ff20245644a190c801b7ee SRPMS/cpio-2.6-22.fc6.src.rpm
1971c968ff5f31b382ff20245644a190c801b7ee noarch/cpio-2.6-22.fc6.src.rpm
2fb6803b35ad1ff3aa06b915e92fd68e879b270a ppc/debug/cpio-debuginfo-2.6-22.fc6.ppc.rpm
52ba8e08409a8a9f070318dece3e24dc4fc4ec4d ppc/cpio-2.6-22.fc6.ppc.rpm
91ab0b03380985d92eb239141e9a671f438003b2 x86_64/cpio-2.6-22.fc6.x86_64.rpm
b0c12ed13635d3b5351ee79df0bc902efff04cd7 x86_64/debug/cpio-debuginfo-2.6-22.fc6.x86_64.rpm
895d04b9436af530af61a8cc6f406973b161b6fc i386/debug/cpio-debuginfo-2.6-22.fc6.i386.rpm
8141c933272979cf16650f484c583958436a491b i386/cpio-2.6-22.fc6.i386.rpm

Fedora 7:

911f30a11bdf2238f1a50b91f83d7d21d9455978 cpio-2.6-28.fc7.ppc64.rpm
2383a135ea76390668742d1bb2a9aa6c70ecb544 cpio-debuginfo-2.6-28.fc7.ppc64.rpm
381a54fed92cf24e362591c12d7162bc96d71817 cpio-2.6-28.fc7.i386.rpm
13c531c898880bc6e3819485551320f85fd8c766 cpio-debuginfo-2.6-28.fc7.i386.rpm
c83be5c1d1f000d648cf869eba2c15c521461305 cpio-debuginfo-2.6-28.fc7.x86_64.rpm
893d61604221551311f239895200d7c41cd5e104 cpio-2.6-28.fc7.x86_64.rpm
e6bb3ed461f30731455796b159fb7b694eff4c29 cpio-debuginfo-2.6-28.fc7.ppc.rpm
74d248d2291c172085b1917e88b685f6d7dcfe09 cpio-2.6-28.fc7.ppc.rpm
96e481bdd62838bfcb95376d1c0d1333a4b8cd96 cpio-2.6-28.fc7.src.rpm

Original Advisory:
https://www.redhat.com/archives/fedor...-announce/2007-November/msg00078.html
https://www.redhat.com/archives/fedor...-announce/2007-November/msg00053.html



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

292 Related Secunia Security Advisories, displaying 10

1. Fedora update for roundcubemail
2. Fedora update for xorg-x11-server
3. Fedora update for kronolith
4. Fedora update for net-snmp
5. Fedora update for openoffice.org
6. Fedora update for evolution
7. Fedora update for snort
8. Fedora update for libpng
9. Fedora update for imlib2
10. Fedora update for samba

Show all related advisories


Send Feedback to Secunia

If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
Apple Safari Cross-Domain Cookie Injection Vulnerability
2.
YouTube Blog Multiple Vulnerabilities
3.
dnsmasq Denial of Service and DNS Cache Poisoning
4.
Moodle Script Insertion and Cross-Site Request Forgery
5.
Asterisk Two Denial of Service Vulnerabilities
6.
Ubuntu update for dnsmasq
7.
Claroline Multiple Cross-Site Scripting Vulnerabilities
8.
Geeklog Forum Plugin Search Cross-Site Scripting Vulnerability
9.
IPCop update for various packages
10.
SocialEngine SQL Injection and Code Execution





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia