View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2015-1197 severity low: SUSE including 16 source package names (cpio, cpio-2.13-150400.1.98, …), 40 product×package rows across 20 product lines (SUSE Linux Enterprise Desktop 11 SP2, SUSE Linux Enterprise Desktop 11 SP3, … (20 product lines)): Fixed 26, Known Not Affected 14.
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.