Vulnerability CVE-2021-31872: Information

Description

An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems may result in a buffer overflow or other security impact.

Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: April 30, 2021
Modified: April 19, 2022
Error type identifier: CWE-190

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
klibcc9f22.0.8-alt2.c9f2.12.0.8-alt2.c9f2.1ALT-PU-2022-1761-1298875Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:klibc_project:klibc:*:*:*:*:*:x86:*:*
      End excliding
      2.0.9

      Configuration 2

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*