cpio used a 0 umask when creating files using the -O (archive) or -F options, which created the files with mode 0666 and allowed local users to read or overwrite those files. (CAN-1999-1572)
For details, fix, etc see http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=238177 from naddy@