Advisories ยป MGASA-2016-0063

Updated cpio packages fix CVE-2016-2037

Publication date: 17 Feb 2016
Modification date: 17 Feb 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-2037

Description

Updated cpio package fixes security vulnerability:

An out-of-bounds write in cpio was found in the parsing of cpio files, in the
process_copy_in() function in src/copyin.c (CVE-2016-2037).
                

References

SRPMS

5/core