SciLinux: CVE-2005-4268 SL4 cpio i386/x86_64
Summary
Date: Wed, 9 May 2007 15:10:27 -0500Reply-To: Connie SiehSender: Security Errata for Scientific Linux From: Connie Sieh Subject: Security ERRATA for SL4 cpio on i386/x86_64Comments: To: scientific Synopsis: Low: cpio security and bug fix updateIssue date: 2007-05-01CVE Names: CVE-2005-4268A buffer overflow was found in cpio on 64-bit platforms. By tricking auser into adding a specially crafted large file to a cpio archive, a localattacker may be able to exploit this flaw to execute arbitrary code withthe target user's privileges. (CVE-2005-4268)SRPMS: cpio-2.5-13.RHEL4.src.rpmi386: cpio-2.5-13.RHEL4.i386.rpmx86_64: cpio-2.5-13.RHEL4.x86_64.rpm-Connie Sieh-Troy Dawson