Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
{ "binaries": [ { "binary_version": "2.13+dfsg-2ubuntu0.4", "binary_name": "cpio" }, { "binary_version": "2.13+dfsg-2ubuntu0.4", "binary_name": "cpio-win32" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "2.13+dfsg-7ubuntu0.1", "binary_name": "cpio" }, { "binary_version": "2.13+dfsg-7ubuntu0.1", "binary_name": "cpio-win32" } ], "availability": "No subscription required" }