Vulnerability Details CVE-2021-38185
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.215
EPSS Ranking 95.3%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.8
Products affected by CVE-2021-38185
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:gnu:cpio:2.5.90
-
-
-
-