CVE-2010-4226

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
06/02/2014
Last modified:
09/06/2025

Description

cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:cpio:*:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:2007.05.10:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:2010.07.28:*:*:*:*:*:*:*