CVE-2023-7207

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
29/02/2024
Last modified:
26/08/2025

Description

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:cpio:2.13:*:*:*:*:*:*:*