This bug was fixed in the package cpio - 2.13+dfsg-7 Sponsored for Heinrich Schuchardt (xypron)
--------------- cpio (2.13+dfsg-7) unstable; urgency=medium [ Salvatore Bonaccorso ] * Fix dynamic string reallocations (Closes: #992192) -- Anibal Monsalve Salazar <ani...@debian.org> Sun, 22 Aug 2021 15:21:53 +1000 cpio (2.13+dfsg-6) unstable; urgency=high * Fix regression of original fix for CVE-2021-38185 Add patch 992098-regression-of-orig-fix-for-CVE-2021-38185 Closes: #992098 -- Anibal Monsalve Salazar <ani...@debian.org> Fri, 13 Aug 2021 13:06:27 +1000 cpio (2.13+dfsg-5) unstable; urgency=medium * Fix CVE-2021-38185 Add patch 992045-CVE-2021-38185-rewrite-dynamic-string-support Closes: #992045 -- Anibal Monsalve Salazar <ani...@debian.org> Wed, 11 Aug 2021 01:18:33 +1000 ** Changed in: cpio (Ubuntu) Status: New => Fix Released ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-38185 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1958131 Title: Sync cpio 2.13+dfsg-7 (main) from Debian sid (main) To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/cpio/+bug/1958131/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs