Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-38185
Description:GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2021.2681   1.3.6.1.4.1.25623.1.1.2.2021.2706   1.3.6.1.4.1.25623.1.0.845047   1.3.6.1.4.1.25623.1.1.2.2021.2654   1.3.6.1.4.1.25623.1.1.10.2021.0423   1.3.6.1.4.1.25623.1.1.1.2.2023.3445   1.3.6.1.4.1.25623.1.1.4.2021.2689.1   1.3.6.1.4.1.25623.1.0.854069   1.3.6.1.4.1.25623.1.1.2.2021.2781   1.3.6.1.4.1.25623.1.1.2.2021.2749   1.3.6.1.4.1.25623.1.1.12.2022.5064.2   1.3.6.1.4.1.25623.1.1.4.2021.14777.1   1.3.6.1.4.1.25623.1.1.12.2023.5064.3   1.3.6.1.4.1.25623.1.1.2.2023.1248   1.3.6.1.4.1.25623.1.1.2.2021.2626   1.3.6.1.4.1.25623.1.1.4.2021.2686.1   1.3.6.1.4.1.25623.1.1.4.2021.2808.1   1.3.6.1.4.1.25623.1.1.4.2021.14788.1   1.3.6.1.4.1.25623.1.1.2.2022.1060  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-38185
https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=dd96882877721703e19272fe25034560b794061b
https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=dd96882877721703e19272fe25034560b794061b
https://github.com/fangqyi/cpiopwn
https://github.com/fangqyi/cpiopwn
https://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00000.html
https://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00000.html
https://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00002.html
https://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00002.html
https://lists.debian.org/debian-lts-announce/2023/06/msg00007.html




© 1998-2025 E-Soft Inc. All rights reserved.