CVE-2023-7216 Information

Description

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process the archiver could follow symlinks outside of the intended directory which could be utilized to run arbitrary commands on the target system.

Reference

https://access.redhat.com/security/cve/CVE-2023-7216 https://bugzilla.redhat.com/show_bug.cgi?id=2249901

Share on: