Debian Security Advisory

DLA-415-1 cpio -- LTS security update

Date Reported:
15 Feb 2016
Affected Packages:
cpio
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 812401.
In Mitre's CVE dictionary: CVE-2016-2037.
More information:

An out-of-bounds write was discovered in the parsing of cpio files. For Debian 6 Squeeze, this issue has been fixed in cpio version 2.11-4+deb6u2.

We recommend you to upgrade your cpio package.