{"id":52355,"date":"2019-11-06T00:00:00","date_gmt":"2019-11-05T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/uyazvimosti-v-cpio-i-libarchive"},"modified":"2020-02-18T14:00:03","modified_gmt":"2020-02-18T11:00:03","slug":"uyazvimosti-v-cpio-i-libarchive","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-cpio-i-libarchive","title":{"rendered":"Vuln\u00e9rabilit\u00e9s dans cpio et libarchive","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Quatre ans apr\u00e8s la derni\u00e8re version <noindex><a rel=\"nofollow\" href=\"https:\/\/www.mail-archive.com\/info-gnu@gnu.org\/msg02668.html\">publi\u00e9e<\/a><\/noindex> le lancement de l'outil d'archivage de fichiers cpio 2.13, utilis\u00e9 dans les paquets RPM et dans initramfs. Cette nouvelle version corrige trois vuln\u00e9rabilit\u00e9s :<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2015-1197\">CVE-2015-1197<\/a><\/noindex> \u2014 permet de remplacer des fichiers en dehors du r\u00e9pertoire dans lequel l'archive est extraite.\n<li class=\"l\">  <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2016-2037\">CVE-2016-2037<\/a><\/noindex> \u2014 conduit \u00e0 l'\u00e9criture dans une zone en dehors du tampon s\u00e9lectionn\u00e9 lors du traitement de fichiers cpio sp\u00e9cialement format\u00e9s;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2019-14866\">CVE-2019-14866<\/a><\/noindex>) \u2014 en raison d'une v\u00e9rification insuffisante de l'en-t\u00eate du fichier TAR, permet, lors de la cr\u00e9ation d'une archive au format TAR \u00e0 partir d'une liste de fichiers, dans le cas o\u00f9 cette liste contient un archive tar sp\u00e9cialement format\u00e9e et tr\u00e8s grande, de cr\u00e9er l'archive r\u00e9sultante, comprenant des fichiers extraits de l'archive tar ajout\u00e9e avec des droits d'acc\u00e8s incorrects.\n<p>    tar cf suffix.tar AUTHORS<br \/>\n    dd if=\/dev\/zero seek=16G bs=1 count=0 of=suffix.tar<br \/>\n    echo suffix.tar | cpio -H tar -o | tar tvf \u2014<\/p>\n<p>    -rw-r\u2014r\u2014 1000\/1000       0 2019-08-30 16:40 suffix.tar<br \/>\n    -rw-r\u2014r\u2014 thomas\/thomas 161 2019-08-30 16:40 AUTHORS<\/p>\n<\/ul>\n<p>De plus, dans la biblioth\u00e8que <noindex><a rel=\"nofollow\" href=\"https:\/\/www.libarchive.org\/\">Libarchive<\/a><\/noindex>, qui fournit des moyens pour travailler avec divers formats d'archives et fichiers compress\u00e9s, <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.firosolutions.com\/exploits\/libarchi\">une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 identifi\u00e9e<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2019-18408\">CVE-2020-10174<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-18408\">CVE-2019-18408<\/a><\/noindex>), qui entra\u00eene un acc\u00e8s \u00e0 un bloc de m\u00e9moire d\u00e9j\u00e0 lib\u00e9r\u00e9 (use-after-free) lors du traitement de fichiers sp\u00e9cialement format\u00e9s au format RAR. Ce probl\u00e8me pourrait potentiellement conduire \u00e0 l'ex\u00e9cution de code malveillant, mais la possibilit\u00e9 d'exploitation est consid\u00e9r\u00e9e comme peu probable (le niveau de gravit\u00e9 est de 4,4 sur 10, c'est-\u00e0-dire que le probl\u00e8me est jug\u00e9 non dangereux). Le probl\u00e8me a \u00e9t\u00e9 abord\u00e9 sans publicit\u00e9 excessive. <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/libarchive\/libarchive\/commit\/b8592ecba2f9e451e1f5cb7ab6dcee8b8e7b3f60\">a \u00e9t\u00e9 corrig\u00e9e<\/a><\/noindex> dans la version <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/libarchive\/libarchive\/releases\/tag\/v3.4.0\">3.4.0<\/a><\/noindex>.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51820\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u043f\u0443\u0441\u0442\u044f \u0447\u0435\u0442\u044b\u0440\u0435 \u0433\u043e\u0434\u0430 \u0441 \u043c\u043e\u043c\u0435\u043d\u0442\u0430 \u043f\u0440\u043e\u0448\u043b\u043e\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 \u0443\u0442\u0438\u043b\u0438\u0442\u044b \u0434\u043b\u044f \u0430\u0440\u0445\u0438\u0432\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0444\u0430\u0439\u043b\u043e\u0432 cpio 2.13, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u0439 \u0432 \u043f\u0430\u043a\u0435\u0442\u0430\u0445 RPM \u0438 \u0432 initramfs. \u0412 \u043d\u043e\u0432\u043e\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438: CVE-2015-1197 &#8212; \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b \u0437\u0430 \u043f\u0440\u0435\u0434\u0435\u043b\u0430\u043c\u0438 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0440\u0430\u0441\u043a\u0440\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u0430\u0440\u0445\u0438\u0432. CVE-2016-2037 &#8212; \u043f\u0440\u0438\u0432\u043e\u0434\u0438\u0442 \u043a \u0437\u0430\u043f\u0438\u0441\u0438 \u0432 \u043e\u0431\u043b\u0430\u0441\u0442\u044c \u0432\u043d\u0435 \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0431\u0443\u0444\u0435\u0440\u0430 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u0444\u0430\u0439\u043b\u043e\u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-52355","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u043f\u0443\u0441\u0442\u044f \u0447\u0435\u0442\u044b\u0440\u0435 \u0433\u043e\u0434\u0430 \u0441 \u043c\u043e\u043c\u0435\u043d\u0442\u0430 \u043f\u0440\u043e\u0448\u043b\u043e\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 \u0443\u0442\u0438\u043b\u0438\u0442\u044b \u0434\u043b\u044f \u0430\u0440\u0445\u0438\u0432\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0444\u0430\u0439\u043b\u043e\u0432 cpio 2.13.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-cpio-i-libarchive\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 cpio \u0438 libarchive | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u043f\u0443\u0441\u0442\u044f \u0447\u0435\u0442\u044b\u0440\u0435 \u0433\u043e\u0434\u0430 \u0441 \u043c\u043e\u043c\u0435\u043d\u0442\u0430 \u043f\u0440\u043e\u0448\u043b\u043e\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 \u0443\u0442\u0438\u043b\u0438\u0442\u044b \u0434\u043b\u044f \u0430\u0440\u0445\u0438\u0432\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0444\u0430\u0439\u043b\u043e\u0432 cpio 2.13.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-cpio-i-libarchive\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-05T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:00:03+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00e9rabilit\u00e9s dans cpio et libarchive | ProHoster","description":"Quatre ans apr\u00e8s la derni\u00e8re version, le lancement de l'outil d'archivage de fichiers cpio 2.13 a \u00e9t\u00e9 publi\u00e9.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-cpio-i-libarchive","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 cpio \u0438 libarchive | ProHoster","og:description":"\u0421\u043f\u0443\u0441\u0442\u044f \u0447\u0435\u0442\u044b\u0440\u0435 \u0433\u043e\u0434\u0430 \u0441 \u043c\u043e\u043c\u0435\u043d\u0442\u0430 \u043f\u0440\u043e\u0448\u043b\u043e\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 \u0443\u0442\u0438\u043b\u0438\u0442\u044b \u0434\u043b\u044f \u0430\u0440\u0445\u0438\u0432\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0444\u0430\u0439\u043b\u043e\u0432 cpio 2.13.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-cpio-i-libarchive","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-05T21:00:00+00:00","article:modified_time":"2020-02-18T11:00:03+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"52355","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 03:20:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:45:28","updated":"2026-01-24 03:20:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/52355","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=52355"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/52355\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=52355"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=52355"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=52355"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}