{"id":"MGASA-2014-0528","summary":"Updated cpio package fixes security vulnerability","details":"Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11\nallows remote attackers to cause a denial of service via a large block value\nin a cpio archive (CVE-2014-9112).\n\nAdditionally, a null pointer dereference in the copyin_link function which\ncould cause a denial of service has also been fixed.\n","modified":"2026-04-16T06:22:22.740722794Z","published":"2014-12-14T14:10:39Z","upstream":["CVE-2014-9112"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0528.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=14765"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1167571"}],"affected":[{"package":{"name":"cpio","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/cpio?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11-6.2.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0528.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}