<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:09:51 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-01329</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-01329</link>
      <description>bdu:2020-01329</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-01329</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2019-14866 — CVE-2019-14866 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2019-14866</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2019-14866</guid>
    </item>
    <item>
      <title>certfr-2021-avi-589 — De multiples vulnérabilités ont été découvertes dans Juniper Junos Space
Log Collector. Certaines d'entre elles permett…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-589</link>
      <description>certfr-2021-avi-589</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-589</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-VM66641 — In all versions of cpio before 2</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-vm66641</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cpio&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the cpio package. In all versions of cpio before 2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cpio&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the cpio package. In all versions of cpio before 2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-vm66641</guid>
    </item>
    <item>
      <title>cnvd-2019-40709</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-40709</link>
      <description>cnvd-2019-40709</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-40709</guid>
    </item>
    <item>
      <title>EUVD-2026-215913</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-215913</link>
      <description>EUVD-2026-215913</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-215913</guid>
    </item>
    <item>
      <title>fkie_cve-2019-14866</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-14866</link>
      <description>&lt;p&gt;In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-14866</guid>
    </item>
    <item>
      <title>GHSA-g3pr-277r-xcx7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g3pr-277r-xcx7</link>
      <description>&lt;p&gt;In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g3pr-277r-xcx7</guid>
    </item>
    <item>
      <title>gsd-2019-14866</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-14866</link>
      <description>gsd-2019-14866</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-14866</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:2593-1 — Security update for cpio</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:2593-1</link>
      <description>&lt;p&gt;Security update for cpio&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for cpio&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:2593-1</guid>
    </item>
    <item>
      <title>RHSA-2021:0949 — Red Hat Security Advisory: Red Hat OpenShift Do openshift/odo-init-image 1.1.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0949</link>
      <description>&lt;p&gt;expat: large number of colons in input makes parser consume high amount of resources, leading to DoS e2fsprogs: Crafted ext4 partition leads to out-of-bounds write e2fsprogs: Out-of-bounds write in e2fsck/rehash.c curl: heap buffer overflow in function tftp_receive_packet() nss: Out-of-bounds read when importing curve25519 private key nss: PKCS#1 v1.5 signatures can be used for TLS 1.3 nss: Use-after-free in sftk_FreeSession due to improper refcounting glib2: file_copy_fallback in gio/gfile.c in GNOME GLib does not properly restrict file permissions while a copy operation is in progress dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass ibus: missing authorization allows local attacker to access the input bus of another user cpio: improper input validation when writing tar header fields leads to unexpected tar generation expat: heap-based buffer over-read via crafted XML input python: XSS vulnerability in the documentation XML-RPC server in server_title field nss: Check length of inputs for cryptographic primitives nss: TLS 1.3 HelloRetryRequest downgrade request sets client into invalid state libssh2: integer overflow in SSH_MSG_DISCONNECT logic in packet.c glibc: LD_PREFER_MAP_32BIT_EXEC not ignored in setuid binaries libxml2: memory leak in xmlParseBalancedChunkMemoryRecover in parser.c systemd: memory leak in button_open() in login/logind-button.c when udev events are received libxml2: memory leak in xmlSchemaPreRun in xmlschemas.c python: infinite loop in the tarfi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;expat: large number of colons in input makes parser consume high amount of resources, leading to DoS e2fsprogs: Crafted ext4 partition leads to out-of-bounds write e2fsprogs: Out-of-bounds write in e2fsck/rehash.c curl: heap buffer overflow in function tftp_receive_packet() nss: Out-of-bounds read when importing curve25519 private key nss: PKCS#1 v1.5 signatures can be used for TLS 1.3 nss: Use-after-free in sftk_FreeSession due to improper refcounting glib2: file_copy_fallback in gio/gfile.c in GNOME GLib does not properly restrict file permissions while a copy operation is in progress dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass ibus: missing authorization allows local attacker to access the input bus of another user cpio: improper input validation when writing tar header fields leads to unexpected tar generation expat: heap-based buffer over-read via crafted XML input python: XSS vulnerability in the documentation XML-RPC server in server_title field nss: Check length of inputs for cryptographic primitives nss: TLS 1.3 HelloRetryRequest downgrade request sets client into invalid state libssh2: integer overflow in SSH_MSG_DISCONNECT logic in packet.c glibc: LD_PREFER_MAP_32BIT_EXEC not ignored in setuid binaries libxml2: memory leak in xmlParseBalancedChunkMemoryRecover in parser.c systemd: memory leak in button_open() in login/logind-button.c when udev events are received libxml2: memory leak in xmlSchemaPreRun in xmlschemas.c python: infinite loop in the tarfi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0949</guid>
    </item>
    <item>
      <title>SSA-202008 — SSA-202008: Multiple Vulnerabilities in Ruggedcom Rox Before V2.17.0</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-202008</link>
      <description>&lt;p&gt;An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used &amp;#34;group blacklisting&amp;#34; (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used &amp;#34;group blacklisting&amp;#34; (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-202008</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:3059-1 — Security update for cpio</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:3059-1</link>
      <description>&lt;p&gt;Security update for cpio&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for cpio&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:3059-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-14866</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-14866</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: cpio, Ubuntu:16.04:LTS: cpio, Ubuntu:18.04:LTS: cpio&lt;/p&gt;
&lt;p&gt;In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: cpio, Ubuntu:16.04:LTS: cpio, Ubuntu:18.04:LTS: cpio&lt;/p&gt;
&lt;p&gt;In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-14866</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1353 — GNU Cpio: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1353</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in GNU Cpio ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in GNU Cpio ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1353</guid>
    </item>
  </channel>
</rss>
