CVE-2020-7667

HIGH

go_rpm_utils < 0.1.0 - Path Traversal via CPIO Extraction

Title source: llm
STIX 2.1

Description

In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-leading ".." which leads in file extraction outside of the current directory. Note: the fixing commit was applied to all affected versions which were re-released.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0160
EPSS Percentile 72.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-22
Status published
Products (2)
sas/go_rpm_utils < 0.1.0
sassoftware/go-rpmutils 0 - 0.1.0Go
Published Jun 24, 2020
Tracked Since Feb 18, 2026