File _patchinfo of Package patchinfo.221

<patchinfo incident="221">
  <issue id="658010" tracker="bnc">VUL-0: cpio directory traversal</issue>
  <issue id="907456" tracker="bnc">VUL-0: CVE-2014-9112: cpio: heap-based buffer overflow flaw in list_file()</issue>
  <issue id="CVE-2014-9112" tracker="cve" />
  <category>security</category>
  <rating>moderate</rating>
  <packager>vitezslav_cizek</packager>
  <description>
This cpio security update fixes the following buffer overflow issue and
two non security issues:

- fix an OOB write with cpio -i (bnc#907456) (CVE-2014-9112)
- prevent cpio from extracting over a symlink (bnc#658010)
- fix a truncation check in mt
</description>
  <summary>Security update for cpio</summary>
</patchinfo>
openSUSE Build Service is sponsored by