Vulnerability record · CVE-2019-14866 · published 7 January 2020
CVE-2019-14866: Gnu cpio improper input validation vulnerability
Gnu · Cpio
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.
Description
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14866 | ExploitIssue TrackingMitigationPatchThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2023/06/msg00007.html | |
| https://lists.gnu.org/archive/html/bug-cpio/2019-08/msg00003.html | Mailing ListPatchThird Party Advisory |
| https://lists.gnu.org/archive/html/bug-cpio/2019-11/msg00000.html | ExploitMailing ListThird Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14866 | ExploitIssue TrackingMitigationPatchThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2023/06/msg00007.html | |
| https://lists.gnu.org/archive/html/bug-cpio/2019-08/msg00003.html | Mailing ListPatchThird Party Advisory |
| https://lists.gnu.org/archive/html/bug-cpio/2019-11/msg00000.html | ExploitMailing ListThird Party Advisory |
Track CVE-2019-14866 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-14866), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.