Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.13+dfsg-2ubuntu0.4", "binary_name": "cpio" }, { "binary_version": "2.13+dfsg-2ubuntu0.4", "binary_name": "cpio-win32" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.13+dfsg-7ubuntu0.1", "binary_name": "cpio" }, { "binary_version": "2.13+dfsg-7ubuntu0.1", "binary_name": "cpio-win32" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.15+dfsg-1ubuntu1", "binary_name": "cpio" } ] }