Secunia Logo
Netsikker nu! 2008
 
Fedora update for cpio
Secunia Advisory: SA27476
Release Date: 2007-11-06
Popularity: 3,016 views

Critical:
Not critical
Impact: DoS
Where: From remote
Solution Status: Vendor Patch

OS:Fedora 7
Fedora Core 6

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2007-4476


Description:
Fedora has issued an update for cpio. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error when processing specially crafted tar archives and can be exploited to cause a stack-based buffer overflow and crash the vulnerable application.

Solution:
Apply updated packages.

Fedora Core 6:

1971c968ff5f31b382ff20245644a190c801b7ee SRPMS/cpio-2.6-22.fc6.src.rpm
1971c968ff5f31b382ff20245644a190c801b7ee noarch/cpio-2.6-22.fc6.src.rpm
2fb6803b35ad1ff3aa06b915e92fd68e879b270a ppc/debug/cpio-debuginfo-2.6-22.fc6.ppc.rpm
52ba8e08409a8a9f070318dece3e24dc4fc4ec4d ppc/cpio-2.6-22.fc6.ppc.rpm
91ab0b03380985d92eb239141e9a671f438003b2 x86_64/cpio-2.6-22.fc6.x86_64.rpm
b0c12ed13635d3b5351ee79df0bc902efff04cd7 x86_64/debug/cpio-debuginfo-2.6-22.fc6.x86_64.rpm
895d04b9436af530af61a8cc6f406973b161b6fc i386/debug/cpio-debuginfo-2.6-22.fc6.i386.rpm
8141c933272979cf16650f484c583958436a491b i386/cpio-2.6-22.fc6.i386.rpm

Fedora 7:

911f30a11bdf2238f1a50b91f83d7d21d9455978 cpio-2.6-28.fc7.ppc64.rpm
2383a135ea76390668742d1bb2a9aa6c70ecb544 cpio-debuginfo-2.6-28.fc7.ppc64.rpm
381a54fed92cf24e362591c12d7162bc96d71817 cpio-2.6-28.fc7.i386.rpm
13c531c898880bc6e3819485551320f85fd8c766 cpio-debuginfo-2.6-28.fc7.i386.rpm
c83be5c1d1f000d648cf869eba2c15c521461305 cpio-debuginfo-2.6-28.fc7.x86_64.rpm
893d61604221551311f239895200d7c41cd5e104 cpio-2.6-28.fc7.x86_64.rpm
e6bb3ed461f30731455796b159fb7b694eff4c29 cpio-debuginfo-2.6-28.fc7.ppc.rpm
74d248d2291c172085b1917e88b685f6d7dcfe09 cpio-2.6-28.fc7.ppc.rpm
96e481bdd62838bfcb95376d1c0d1333a4b8cd96 cpio-2.6-28.fc7.src.rpm

Original Advisory:
https://www.redhat.com/archives/fedor...-announce/2007-November/msg00078.html
https://www.redhat.com/archives/fedor...-announce/2007-November/msg00053.html


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Today
New advisories: 19
New vulnerabilities: 68
Updated advisories: 62

Moderately // 246 views
Debian update for php5
Moderately // 183 views
Atarone CMS Multiple Vulnerabilities
Moderately // 214 views
Debian update for squid
Less // 219 views
SUSE update for mercurial
Moderately // 263 views
SUSE update for openssh
Less // 206 views
Fedora update for mediawiki

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Debian update for php5 // 55 views
2. Juniper Products Neighbor Discovery Protocol Neighbor Solicitation Vulnerability // 39 views
3. CMME Information Disclosure Security Issues // 37 views
4. H-Sphere webshell4 Cross-Site Scripting and Request Forgery // 36 views
5. Atarone CMS Multiple Vulnerabilities // 35 views
6. Debian update for squid // 34 views
7. SUSE update for openssh // 32 views
8. Fedora update for mediawiki // 29 views
9. MetaGauge Directory Traversal Vulnerability // 27 views
10. HP-UX NFS/ONCplus Denial of Service Vulnerability // 27 views