ELA-187-1 cpio security update
Package: cpio
Version: 2.11+dfsg-0.1+deb7u3
Related CVE: CVE-2019-14866
It is possible for an attacker to create a file so when backed up with cpio can generate arbitrary files in the resulting tar archive. When the backup is restored the file is then created with arbitrary permissions.
For Debian 7 Wheezy, these problems have been fixed in version 2.11+dfsg-0.1+deb7u3.
We recommend that you upgrade your cpio packages.
Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/
A cpio security update has been released for Debian GNU/Linux 7 Extended LTS