Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2016-3697 (GCVE-0-2016-3697)
Vulnerability from cvelistv5
Published
2016-06-01 20:00
Modified
2024-08-06 00:03
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- n/a
Summary
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
References
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-06T00:03:34.441Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "RHSA-2016:1034", "tags": [ "vendor-advisory", "x_refsource_REDHAT", "x_transferred" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-1034.html" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://github.com/opencontainers/runc/releases/tag/v0.1.0" }, { "name": "openSUSE-SU-2016:1417", "tags": [ "vendor-advisory", "x_refsource_SUSE", "x_transferred" ], "url": "http://lists.opensuse.org/opensuse-updates/2016-05/msg00111.html" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://github.com/docker/docker/issues/21436" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://github.com/opencontainers/runc/pull/708" }, { "name": "RHSA-2016:2634", "tags": [ "vendor-advisory", "x_refsource_REDHAT", "x_transferred" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-2634.html" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091" }, { "name": "GLSA-201612-28", "tags": [ "vendor-advisory", "x_refsource_GENTOO", "x_transferred" ], "url": "https://security.gentoo.org/glsa/201612-28" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "datePublic": "2016-03-23T00:00:00", "descriptions": [ { "lang": "en", "value": "libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-06-30T16:57:01", "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat" }, "references": [ { "name": "RHSA-2016:1034", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-1034.html" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://github.com/opencontainers/runc/releases/tag/v0.1.0" }, { "name": "openSUSE-SU-2016:1417", "tags": [ "vendor-advisory", "x_refsource_SUSE" ], "url": "http://lists.opensuse.org/opensuse-updates/2016-05/msg00111.html" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://github.com/docker/docker/issues/21436" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://github.com/opencontainers/runc/pull/708" }, { "name": "RHSA-2016:2634", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-2634.html" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091" }, { "name": "GLSA-201612-28", "tags": [ "vendor-advisory", "x_refsource_GENTOO" ], "url": "https://security.gentoo.org/glsa/201612-28" } ] } }, "cveMetadata": { "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "assignerShortName": "redhat", "cveId": "CVE-2016-3697", "datePublished": "2016-06-01T20:00:00", "dateReserved": "2016-03-30T00:00:00", "dateUpdated": "2024-08-06T00:03:34.441Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2016-3697\",\"sourceIdentifier\":\"secalert@redhat.com\",\"published\":\"2016-06-01T20:59:06.137\",\"lastModified\":\"2025-04-12T10:46:40.837\",\"vulnStatus\":\"Deferred\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.\"},{\"lang\":\"es\",\"value\":\"libcontainer/user/user.go en runC en versiones anteriores a 0.1.0, tal como se utiliza en Docker en versiones anteriores a 1.11.2, trata indebidamente un UID num\u00e9rico como un nombre de usuario potencial, lo que permite a usuarios locales obtener privilegios a trav\u00e9s de un nombre de usuario num\u00e9rico en el archivo password en un contenedor.\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\",\"baseScore\":7.8,\"baseSeverity\":\"HIGH\",\"attackVector\":\"LOCAL\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"LOW\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"HIGH\",\"integrityImpact\":\"HIGH\",\"availabilityImpact\":\"HIGH\"},\"exploitabilityScore\":1.8,\"impactScore\":5.9}],\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:L/AC:L/Au:N/C:P/I:N/A:N\",\"baseScore\":2.1,\"accessVector\":\"LOCAL\",\"accessComplexity\":\"LOW\",\"authentication\":\"NONE\",\"confidentialityImpact\":\"PARTIAL\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"NONE\"},\"baseSeverity\":\"LOW\",\"exploitabilityScore\":3.9,\"impactScore\":2.9,\"acInsufInfo\":false,\"obtainAllPrivilege\":false,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":false}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-264\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:*\",\"versionEndIncluding\":\"1.11.1\",\"matchCriteriaId\":\"F8698BF1-AB4E-4AF8-89DE-A398CBD11176\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*\",\"versionEndIncluding\":\"0.0.9\",\"matchCriteriaId\":\"B7483C33-6AB0-4C35-BCAF-A80193AB8723\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"03117DF1-3BEC-4B8D-AD63-DBBDB2126081\"}]}]}],\"references\":[{\"url\":\"http://lists.opensuse.org/opensuse-updates/2016-05/msg00111.html\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"http://rhn.redhat.com/errata/RHSA-2016-1034.html\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://rhn.redhat.com/errata/RHSA-2016-2634.html\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://github.com/docker/docker/issues/21436\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Patch\",\"Third Party Advisory\"]},{\"url\":\"https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://github.com/opencontainers/runc/pull/708\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://github.com/opencontainers/runc/releases/tag/v0.1.0\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Patch\",\"Third Party Advisory\"]},{\"url\":\"https://security.gentoo.org/glsa/201612-28\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://lists.opensuse.org/opensuse-updates/2016-05/msg00111.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"http://rhn.redhat.com/errata/RHSA-2016-1034.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://rhn.redhat.com/errata/RHSA-2016-2634.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://github.com/docker/docker/issues/21436\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Patch\",\"Third Party Advisory\"]},{\"url\":\"https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://github.com/opencontainers/runc/pull/708\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://github.com/opencontainers/runc/releases/tag/v0.1.0\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Patch\",\"Third Party Advisory\"]},{\"url\":\"https://security.gentoo.org/glsa/201612-28\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]}]}}" } }
fkie_cve-2016-3697
Vulnerability from fkie_nvd
Published
2016-06-01 20:59
Modified
2025-04-12 10:46
Severity ?
Summary
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
References
▶ | URL | Tags | |
---|---|---|---|
secalert@redhat.com | http://lists.opensuse.org/opensuse-updates/2016-05/msg00111.html | Mailing List, Third Party Advisory | |
secalert@redhat.com | http://rhn.redhat.com/errata/RHSA-2016-1034.html | Third Party Advisory | |
secalert@redhat.com | http://rhn.redhat.com/errata/RHSA-2016-2634.html | Third Party Advisory | |
secalert@redhat.com | https://github.com/docker/docker/issues/21436 | Patch, Third Party Advisory | |
secalert@redhat.com | https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091 | Third Party Advisory | |
secalert@redhat.com | https://github.com/opencontainers/runc/pull/708 | Third Party Advisory | |
secalert@redhat.com | https://github.com/opencontainers/runc/releases/tag/v0.1.0 | Patch, Third Party Advisory | |
secalert@redhat.com | https://security.gentoo.org/glsa/201612-28 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://lists.opensuse.org/opensuse-updates/2016-05/msg00111.html | Mailing List, Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://rhn.redhat.com/errata/RHSA-2016-1034.html | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://rhn.redhat.com/errata/RHSA-2016-2634.html | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://github.com/docker/docker/issues/21436 | Patch, Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://github.com/opencontainers/runc/pull/708 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://github.com/opencontainers/runc/releases/tag/v0.1.0 | Patch, Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://security.gentoo.org/glsa/201612-28 | Third Party Advisory |
Impacted products
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:*", "matchCriteriaId": "F8698BF1-AB4E-4AF8-89DE-A398CBD11176", "versionEndIncluding": "1.11.1", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*", "matchCriteriaId": "B7483C33-6AB0-4C35-BCAF-A80193AB8723", "versionEndIncluding": "0.0.9", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*", "matchCriteriaId": "03117DF1-3BEC-4B8D-AD63-DBBDB2126081", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container." }, { "lang": "es", "value": "libcontainer/user/user.go en runC en versiones anteriores a 0.1.0, tal como se utiliza en Docker en versiones anteriores a 1.11.2, trata indebidamente un UID num\u00e9rico como un nombre de usuario potencial, lo que permite a usuarios locales obtener privilegios a trav\u00e9s de un nombre de usuario num\u00e9rico en el archivo password en un contenedor." } ], "id": "CVE-2016-3697", "lastModified": "2025-04-12T10:46:40.837", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "LOW", "cvssData": { "accessComplexity": "LOW", "accessVector": "LOCAL", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 2.1, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N", "version": "2.0" }, "exploitabilityScore": 3.9, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2016-06-01T20:59:06.137", "references": [ { "source": "secalert@redhat.com", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://lists.opensuse.org/opensuse-updates/2016-05/msg00111.html" }, { "source": "secalert@redhat.com", "tags": [ "Third Party Advisory" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-1034.html" }, { "source": "secalert@redhat.com", "tags": [ "Third Party Advisory" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-2634.html" }, { "source": "secalert@redhat.com", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/docker/docker/issues/21436" }, { "source": "secalert@redhat.com", "tags": [ "Third Party Advisory" ], "url": "https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091" }, { "source": "secalert@redhat.com", "tags": [ "Third Party Advisory" ], "url": "https://github.com/opencontainers/runc/pull/708" }, { "source": "secalert@redhat.com", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/opencontainers/runc/releases/tag/v0.1.0" }, { "source": "secalert@redhat.com", "tags": [ "Third Party Advisory" ], "url": "https://security.gentoo.org/glsa/201612-28" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://lists.opensuse.org/opensuse-updates/2016-05/msg00111.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-1034.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-2634.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/docker/docker/issues/21436" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://github.com/opencontainers/runc/pull/708" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/opencontainers/runc/releases/tag/v0.1.0" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://security.gentoo.org/glsa/201612-28" } ], "sourceIdentifier": "secalert@redhat.com", "vulnStatus": "Deferred", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-264" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
opensuse-su-2024:10532-1
Vulnerability from csaf_opensuse
Published
2024-06-15 00:00
Modified
2024-06-15 00:00
Summary
docker-1.12.3-4.1 on GA media
Notes
Title of the patch
docker-1.12.3-4.1 on GA media
Description of the patch
These are all security issues fixed in the docker-1.12.3-4.1 package on the GA media of openSUSE Tumbleweed.
Patchnames
openSUSE-Tumbleweed-2024-10532
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "docker-1.12.3-4.1 on GA media", "title": "Title of the patch" }, { "category": "description", "text": "These are all security issues fixed in the docker-1.12.3-4.1 package on the GA media of openSUSE Tumbleweed.", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-Tumbleweed-2024-10532", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_10532-1.json" }, { "category": "self", "summary": "SUSE CVE CVE-2014-3499 page", "url": "https://www.suse.com/security/cve/CVE-2014-3499/" }, { "category": "self", "summary": "SUSE CVE CVE-2014-5277 page", "url": "https://www.suse.com/security/cve/CVE-2014-5277/" }, { "category": "self", "summary": "SUSE CVE CVE-2014-6407 page", "url": "https://www.suse.com/security/cve/CVE-2014-6407/" }, { "category": "self", "summary": "SUSE CVE CVE-2014-6408 page", "url": "https://www.suse.com/security/cve/CVE-2014-6408/" }, { "category": "self", "summary": "SUSE CVE CVE-2014-8178 page", "url": "https://www.suse.com/security/cve/CVE-2014-8178/" }, { "category": "self", "summary": "SUSE CVE CVE-2014-8179 page", "url": "https://www.suse.com/security/cve/CVE-2014-8179/" }, { "category": "self", "summary": "SUSE CVE CVE-2014-9356 page", "url": "https://www.suse.com/security/cve/CVE-2014-9356/" }, { "category": "self", "summary": "SUSE CVE CVE-2014-9357 page", "url": "https://www.suse.com/security/cve/CVE-2014-9357/" }, { "category": "self", "summary": "SUSE CVE CVE-2014-9358 page", "url": "https://www.suse.com/security/cve/CVE-2014-9358/" }, { "category": "self", "summary": "SUSE CVE CVE-2015-3627 page", "url": "https://www.suse.com/security/cve/CVE-2015-3627/" }, { "category": "self", "summary": "SUSE CVE CVE-2015-3629 page", "url": "https://www.suse.com/security/cve/CVE-2015-3629/" }, { "category": "self", "summary": "SUSE CVE CVE-2015-3630 page", "url": "https://www.suse.com/security/cve/CVE-2015-3630/" }, { "category": "self", "summary": "SUSE CVE CVE-2015-3631 page", "url": "https://www.suse.com/security/cve/CVE-2015-3631/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-3697 page", "url": "https://www.suse.com/security/cve/CVE-2016-3697/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-8867 page", "url": "https://www.suse.com/security/cve/CVE-2016-8867/" } ], "title": "docker-1.12.3-4.1 on GA media", "tracking": { "current_release_date": "2024-06-15T00:00:00Z", "generator": { "date": "2024-06-15T00:00:00Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2024:10532-1", "initial_release_date": "2024-06-15T00:00:00Z", "revision_history": [ { "date": "2024-06-15T00:00:00Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "docker-1.12.3-4.1.aarch64", "product": { "name": "docker-1.12.3-4.1.aarch64", "product_id": "docker-1.12.3-4.1.aarch64" } }, { "category": "product_version", "name": "docker-bash-completion-1.12.3-4.1.aarch64", "product": { "name": "docker-bash-completion-1.12.3-4.1.aarch64", "product_id": "docker-bash-completion-1.12.3-4.1.aarch64" } }, { "category": "product_version", "name": "docker-test-1.12.3-4.1.aarch64", "product": { "name": "docker-test-1.12.3-4.1.aarch64", "product_id": "docker-test-1.12.3-4.1.aarch64" } }, { "category": "product_version", "name": "docker-zsh-completion-1.12.3-4.1.aarch64", "product": { "name": "docker-zsh-completion-1.12.3-4.1.aarch64", "product_id": "docker-zsh-completion-1.12.3-4.1.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "docker-1.12.3-4.1.ppc64le", "product": { "name": "docker-1.12.3-4.1.ppc64le", "product_id": "docker-1.12.3-4.1.ppc64le" } }, { "category": "product_version", "name": "docker-bash-completion-1.12.3-4.1.ppc64le", "product": { "name": "docker-bash-completion-1.12.3-4.1.ppc64le", "product_id": "docker-bash-completion-1.12.3-4.1.ppc64le" } }, { "category": "product_version", "name": "docker-test-1.12.3-4.1.ppc64le", "product": { "name": "docker-test-1.12.3-4.1.ppc64le", "product_id": "docker-test-1.12.3-4.1.ppc64le" } }, { "category": "product_version", "name": "docker-zsh-completion-1.12.3-4.1.ppc64le", "product": { "name": "docker-zsh-completion-1.12.3-4.1.ppc64le", "product_id": "docker-zsh-completion-1.12.3-4.1.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "docker-1.12.3-4.1.s390x", "product": { "name": "docker-1.12.3-4.1.s390x", "product_id": "docker-1.12.3-4.1.s390x" } }, { "category": "product_version", "name": "docker-bash-completion-1.12.3-4.1.s390x", "product": { "name": "docker-bash-completion-1.12.3-4.1.s390x", "product_id": "docker-bash-completion-1.12.3-4.1.s390x" } }, { "category": "product_version", "name": "docker-test-1.12.3-4.1.s390x", "product": { "name": "docker-test-1.12.3-4.1.s390x", "product_id": "docker-test-1.12.3-4.1.s390x" } }, { "category": "product_version", "name": "docker-zsh-completion-1.12.3-4.1.s390x", "product": { "name": "docker-zsh-completion-1.12.3-4.1.s390x", "product_id": "docker-zsh-completion-1.12.3-4.1.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "docker-1.12.3-4.1.x86_64", "product": { "name": "docker-1.12.3-4.1.x86_64", "product_id": "docker-1.12.3-4.1.x86_64" } }, { "category": "product_version", "name": "docker-bash-completion-1.12.3-4.1.x86_64", "product": { "name": "docker-bash-completion-1.12.3-4.1.x86_64", "product_id": "docker-bash-completion-1.12.3-4.1.x86_64" } }, { "category": "product_version", "name": "docker-test-1.12.3-4.1.x86_64", "product": { "name": "docker-test-1.12.3-4.1.x86_64", "product_id": "docker-test-1.12.3-4.1.x86_64" } }, { "category": "product_version", "name": "docker-zsh-completion-1.12.3-4.1.x86_64", "product": { "name": "docker-zsh-completion-1.12.3-4.1.x86_64", "product_id": "docker-zsh-completion-1.12.3-4.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "openSUSE Tumbleweed", "product": { "name": "openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed", "product_identification_helper": { "cpe": "cpe:/o:opensuse:tumbleweed" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "docker-1.12.3-4.1.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64" }, "product_reference": "docker-1.12.3-4.1.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-1.12.3-4.1.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le" }, "product_reference": "docker-1.12.3-4.1.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-1.12.3-4.1.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x" }, "product_reference": "docker-1.12.3-4.1.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-1.12.3-4.1.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64" }, "product_reference": "docker-1.12.3-4.1.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-bash-completion-1.12.3-4.1.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64" }, "product_reference": "docker-bash-completion-1.12.3-4.1.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-bash-completion-1.12.3-4.1.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le" }, "product_reference": "docker-bash-completion-1.12.3-4.1.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-bash-completion-1.12.3-4.1.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x" }, "product_reference": "docker-bash-completion-1.12.3-4.1.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-bash-completion-1.12.3-4.1.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64" }, "product_reference": "docker-bash-completion-1.12.3-4.1.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-test-1.12.3-4.1.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64" }, "product_reference": "docker-test-1.12.3-4.1.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-test-1.12.3-4.1.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le" }, "product_reference": "docker-test-1.12.3-4.1.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-test-1.12.3-4.1.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x" }, "product_reference": "docker-test-1.12.3-4.1.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-test-1.12.3-4.1.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64" }, "product_reference": "docker-test-1.12.3-4.1.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-zsh-completion-1.12.3-4.1.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64" }, "product_reference": "docker-zsh-completion-1.12.3-4.1.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-zsh-completion-1.12.3-4.1.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le" }, "product_reference": "docker-zsh-completion-1.12.3-4.1.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-zsh-completion-1.12.3-4.1.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x" }, "product_reference": "docker-zsh-completion-1.12.3-4.1.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "docker-zsh-completion-1.12.3-4.1.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" }, "product_reference": "docker-zsh-completion-1.12.3-4.1.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" } ] }, "vulnerabilities": [ { "cve": "CVE-2014-3499", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2014-3499" } ], "notes": [ { "category": "general", "text": "Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2014-3499", "url": "https://www.suse.com/security/cve/CVE-2014-3499" }, { "category": "external", "summary": "SUSE Bug 885209 for CVE-2014-3499", "url": "https://bugzilla.suse.com/885209" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2014-3499" }, { "cve": "CVE-2014-5277", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2014-5277" } ], "notes": [ { "category": "general", "text": "Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2014-5277", "url": "https://www.suse.com/security/cve/CVE-2014-5277" }, { "category": "external", "summary": "SUSE Bug 904165 for CVE-2014-5277", "url": "https://bugzilla.suse.com/904165" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2014-5277" }, { "cve": "CVE-2014-6407", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2014-6407" } ], "notes": [ { "category": "general", "text": "Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2014-6407", "url": "https://www.suse.com/security/cve/CVE-2014-6407" }, { "category": "external", "summary": "SUSE Bug 907012 for CVE-2014-6407", "url": "https://bugzilla.suse.com/907012" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2014-6407" }, { "cve": "CVE-2014-6408", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2014-6408" } ], "notes": [ { "category": "general", "text": "Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applying unspecified security options to an image.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2014-6408", "url": "https://www.suse.com/security/cve/CVE-2014-6408" }, { "category": "external", "summary": "SUSE Bug 907014 for CVE-2014-6408", "url": "https://bugzilla.suse.com/907014" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2014-6408" }, { "cve": "CVE-2014-8178", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2014-8178" } ], "notes": [ { "category": "general", "text": "Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2014-8178", "url": "https://www.suse.com/security/cve/CVE-2014-8178" }, { "category": "external", "summary": "SUSE Bug 949660 for CVE-2014-8178", "url": "https://bugzilla.suse.com/949660" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2014-8178" }, { "cve": "CVE-2014-8179", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2014-8179" } ], "notes": [ { "category": "general", "text": "Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2014-8179", "url": "https://www.suse.com/security/cve/CVE-2014-8179" }, { "category": "external", "summary": "SUSE Bug 949660 for CVE-2014-8179", "url": "https://bugzilla.suse.com/949660" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2014-8179" }, { "cve": "CVE-2014-9356", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2014-9356" } ], "notes": [ { "category": "general", "text": "Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2014-9356", "url": "https://www.suse.com/security/cve/CVE-2014-9356" }, { "category": "external", "summary": "SUSE Bug 909712 for CVE-2014-9356", "url": "https://bugzilla.suse.com/909712" }, { "category": "external", "summary": "SUSE Bug 909747 for CVE-2014-9356", "url": "https://bugzilla.suse.com/909747" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.6, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2014-9356" }, { "cve": "CVE-2014-9357", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2014-9357" } ], "notes": [ { "category": "general", "text": "Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the chroot for archive extraction.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2014-9357", "url": "https://www.suse.com/security/cve/CVE-2014-9357" }, { "category": "external", "summary": "SUSE Bug 909710 for CVE-2014-9357", "url": "https://bugzilla.suse.com/909710" }, { "category": "external", "summary": "SUSE Bug 909747 for CVE-2014-9357", "url": "https://bugzilla.suse.com/909747" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2014-9357" }, { "cve": "CVE-2014-9358", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2014-9358" } ], "notes": [ { "category": "general", "text": "Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) \"docker load\" operation or (2) \"registry communications.\"", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2014-9358", "url": "https://www.suse.com/security/cve/CVE-2014-9358" }, { "category": "external", "summary": "SUSE Bug 909709 for CVE-2014-9358", "url": "https://bugzilla.suse.com/909709" }, { "category": "external", "summary": "SUSE Bug 909747 for CVE-2014-9358", "url": "https://bugzilla.suse.com/909747" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2014-9358" }, { "cve": "CVE-2015-3627", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2015-3627" } ], "notes": [ { "category": "general", "text": "Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2015-3627", "url": "https://www.suse.com/security/cve/CVE-2015-3627" }, { "category": "external", "summary": "SUSE Bug 930235 for CVE-2015-3627", "url": "https://bugzilla.suse.com/930235" }, { "category": "external", "summary": "SUSE Bug 945060 for CVE-2015-3627", "url": "https://bugzilla.suse.com/945060" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "low" } ], "title": "CVE-2015-3627" }, { "cve": "CVE-2015-3629", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2015-3629" } ], "notes": [ { "category": "general", "text": "Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization (\"mount namespace breakout\") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2015-3629", "url": "https://www.suse.com/security/cve/CVE-2015-3629" }, { "category": "external", "summary": "SUSE Bug 930235 for CVE-2015-3629", "url": "https://bugzilla.suse.com/930235" }, { "category": "external", "summary": "SUSE Bug 945060 for CVE-2015-3629", "url": "https://bugzilla.suse.com/945060" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2015-3629" }, { "cve": "CVE-2015-3630", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2015-3630" } ], "notes": [ { "category": "general", "text": "Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2015-3630", "url": "https://www.suse.com/security/cve/CVE-2015-3630" }, { "category": "external", "summary": "SUSE Bug 930235 for CVE-2015-3630", "url": "https://bugzilla.suse.com/930235" }, { "category": "external", "summary": "SUSE Bug 945060 for CVE-2015-3630", "url": "https://bugzilla.suse.com/945060" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2015-3630" }, { "cve": "CVE-2015-3631", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2015-3631" } ], "notes": [ { "category": "general", "text": "Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2015-3631", "url": "https://www.suse.com/security/cve/CVE-2015-3631" }, { "category": "external", "summary": "SUSE Bug 930235 for CVE-2015-3631", "url": "https://bugzilla.suse.com/930235" }, { "category": "external", "summary": "SUSE Bug 945060 for CVE-2015-3631", "url": "https://bugzilla.suse.com/945060" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "low" } ], "title": "CVE-2015-3631" }, { "cve": "CVE-2016-3697", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-3697" } ], "notes": [ { "category": "general", "text": "libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-3697", "url": "https://www.suse.com/security/cve/CVE-2016-3697" }, { "category": "external", "summary": "SUSE Bug 976777 for CVE-2016-3697", "url": "https://bugzilla.suse.com/976777" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-3697" }, { "cve": "CVE-2016-8867", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-8867" } ], "notes": [ { "category": "general", "text": "Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-8867", "url": "https://www.suse.com/security/cve/CVE-2016-8867" }, { "category": "external", "summary": "SUSE Bug 1007249 for CVE-2016-8867", "url": "https://bugzilla.suse.com/1007249" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:docker-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-bash-completion-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-test-1.12.3-4.1.x86_64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.aarch64", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.ppc64le", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.s390x", "openSUSE Tumbleweed:docker-zsh-completion-1.12.3-4.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2016-8867" } ] }
suse-su-2016:1159-1
Vulnerability from csaf_suse
Published
2016-04-26 12:32
Modified
2016-04-26 12:32
Summary
Security update for docker
Notes
Title of the patch
Security update for docker
Description of the patch
docker was updated to fix one security issue.
This security issue was fixed:
- CVE-2016-3697: Potential privilege escalation via confusion of usernames and UIDs (bsc#976777).
Patchnames
SUSE-OpenStack-Cloud-6-2016-682,SUSE-SLE-Module-Containers-12-2016-682
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for docker", "title": "Title of the patch" }, { "category": "description", "text": "docker was updated to fix one security issue.\n\nThis security issue was fixed:\n- CVE-2016-3697: Potential privilege escalation via confusion of usernames and UIDs (bsc#976777).\n ", "title": "Description of the patch" }, { "category": "details", "text": "SUSE-OpenStack-Cloud-6-2016-682,SUSE-SLE-Module-Containers-12-2016-682", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2016_1159-1.json" }, { "category": "self", "summary": "URL for SUSE-SU-2016:1159-1", "url": "https://www.suse.com/support/update/announcement/2016/suse-su-20161159-1/" }, { "category": "self", "summary": "E-Mail link for SUSE-SU-2016:1159-1", "url": "https://lists.suse.com/pipermail/sle-security-updates/2016-April/002030.html" }, { "category": "self", "summary": "SUSE Bug 976777", "url": "https://bugzilla.suse.com/976777" }, { "category": "self", "summary": "SUSE CVE CVE-2016-3697 page", "url": "https://www.suse.com/security/cve/CVE-2016-3697/" } ], "title": "Security update for docker", "tracking": { "current_release_date": "2016-04-26T12:32:54Z", "generator": { "date": "2016-04-26T12:32:54Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "SUSE-SU-2016:1159-1", "initial_release_date": "2016-04-26T12:32:54Z", "revision_history": [ { "date": "2016-04-26T12:32:54Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "docker-1.10.3-66.1.ppc64le", "product": { "name": "docker-1.10.3-66.1.ppc64le", "product_id": "docker-1.10.3-66.1.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "docker-1.10.3-66.1.s390x", "product": { "name": "docker-1.10.3-66.1.s390x", "product_id": "docker-1.10.3-66.1.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "docker-1.10.3-66.1.x86_64", "product": { "name": "docker-1.10.3-66.1.x86_64", "product_id": "docker-1.10.3-66.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE OpenStack Cloud 6", "product": { "name": "SUSE OpenStack Cloud 6", "product_id": "SUSE OpenStack Cloud 6", "product_identification_helper": { "cpe": "cpe:/o:suse:suse-openstack-cloud:6" } } }, { "category": "product_name", "name": "SUSE Linux Enterprise Module for Containers 12", "product": { "name": "SUSE Linux Enterprise Module for Containers 12", "product_id": "SUSE Linux Enterprise Module for Containers 12", "product_identification_helper": { "cpe": "cpe:/o:suse:sle-module-containers:12" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "docker-1.10.3-66.1.x86_64 as component of SUSE OpenStack Cloud 6", "product_id": "SUSE OpenStack Cloud 6:docker-1.10.3-66.1.x86_64" }, "product_reference": "docker-1.10.3-66.1.x86_64", "relates_to_product_reference": "SUSE OpenStack Cloud 6" }, { "category": "default_component_of", "full_product_name": { "name": "docker-1.10.3-66.1.ppc64le as component of SUSE Linux Enterprise Module for Containers 12", "product_id": "SUSE Linux Enterprise Module for Containers 12:docker-1.10.3-66.1.ppc64le" }, "product_reference": "docker-1.10.3-66.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Module for Containers 12" }, { "category": "default_component_of", "full_product_name": { "name": "docker-1.10.3-66.1.s390x as component of SUSE Linux Enterprise Module for Containers 12", "product_id": "SUSE Linux Enterprise Module for Containers 12:docker-1.10.3-66.1.s390x" }, "product_reference": "docker-1.10.3-66.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Module for Containers 12" }, { "category": "default_component_of", "full_product_name": { "name": "docker-1.10.3-66.1.x86_64 as component of SUSE Linux Enterprise Module for Containers 12", "product_id": "SUSE Linux Enterprise Module for Containers 12:docker-1.10.3-66.1.x86_64" }, "product_reference": "docker-1.10.3-66.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Containers 12" } ] }, "vulnerabilities": [ { "cve": "CVE-2016-3697", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-3697" } ], "notes": [ { "category": "general", "text": "libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Containers 12:docker-1.10.3-66.1.ppc64le", "SUSE Linux Enterprise Module for Containers 12:docker-1.10.3-66.1.s390x", "SUSE Linux Enterprise Module for Containers 12:docker-1.10.3-66.1.x86_64", "SUSE OpenStack Cloud 6:docker-1.10.3-66.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-3697", "url": "https://www.suse.com/security/cve/CVE-2016-3697" }, { "category": "external", "summary": "SUSE Bug 976777 for CVE-2016-3697", "url": "https://bugzilla.suse.com/976777" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Containers 12:docker-1.10.3-66.1.ppc64le", "SUSE Linux Enterprise Module for Containers 12:docker-1.10.3-66.1.s390x", "SUSE Linux Enterprise Module for Containers 12:docker-1.10.3-66.1.x86_64", "SUSE OpenStack Cloud 6:docker-1.10.3-66.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Containers 12:docker-1.10.3-66.1.ppc64le", "SUSE Linux Enterprise Module for Containers 12:docker-1.10.3-66.1.s390x", "SUSE Linux Enterprise Module for Containers 12:docker-1.10.3-66.1.x86_64", "SUSE OpenStack Cloud 6:docker-1.10.3-66.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-04-26T12:32:54Z", "details": "moderate" } ], "title": "CVE-2016-3697" } ] }
rhsa-2016:1034
Vulnerability from csaf_redhat
Published
2016-05-12 15:15
Modified
2024-11-22 10:01
Summary
Red Hat Security Advisory: docker security, bug fix, and enhancement update
Notes
Topic
An update for docker is now available for Red Hat Enterprise Linux 7 Extras.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Details
Docker is an open-source engine that automates the deployment of any application as a lightweight, portable, self-sufficient container that will run virtually anywhere.
Security Fix(es):
* It was found that Docker would launch containers under the specified UID instead of a username. An attacker able to launch a container could use this flaw to escalate their privileges to root within the launched container. (CVE-2016-3697)
This issue was discovered by Mrunal Patel (Red Hat).
Bug Fix(es):
* The process of pulling an image spawns a new "goroutine" for each layer in the image manifest. If any of these downloads, everything stops and an error is returned, even though other goroutines would still be running and writing output through a progress reader which is attached to an http response writer. Since the request handler had already returned from the first error, the http server panics when one of these download goroutines makes a write to the response writer buffer. This bug has been fixed, and docker no longer panics when pulling an image. (BZ#1264562)
* Previously, in certain situations, a container rootfs remained busy during container removal. This typically happened if a container mount point leaked into another mount namespace. As a consequence, container removal failed. To fix this bug, a new docker daemon option "dm.use_deferred_deletion" has been provided. If set to true, this option will defer the container rootfs deletion. The user will see success on container removal but the actual thin device backing the rootfs will be deleted later when it is not busy anymore. (BZ#1190492)
* Previously, the Docker unit file had the "Restart" option set to "on-failure". Consequently, the docker daemon was forced to restart even in cases where it couldn't be started because of configuration or other issues and this situation forced unnecessary restarts of the docker-storage-setup service in a loop. This also caused real error messages to be lost due to so many restarts. To fix this bug, "Restart=on-failure" has been replaced with "Restart=on-abnormal" in the docker unit file. As a result, the docker daemon will not automatically restart if it fails with an unclean exit code. (BZ#1319783)
* Previously, the request body was incorrectly read twice by the docker daemon and consequently, an EOF error was returned. To fix this bug, the code which incorrectly read the request body the first time has been removed. As a result, the EOF error is no longer returned and the body is correctly read when really needed. (BZ#1329743)
Enhancement(s):
* The /usr/bin/docker script now calls /usr/bin/docker-current or /usr/bin/docker-latest based on the value of the sysconfig variable DOCKERBINARY present in /etc/sysconfig/docker. /usr/bin/docker and /etc/sysconfig/docker provided by the docker-common package allow the admin to configure which docker client binary gets called. /usr/bin/docker will call /usr/bin/docker-latest by default when docker is not installed. If docker is installed, /usr/bin/docker will call /usr/bin/docker-current by default, unless DOCKERBINARY is set to /usr/bin/docker-latest in /etc/sysconfig/docker. This way, you can use docker-latest or docker without the need to check which version of the daemon is currently running. (BZ#1328219)
Terms of Use
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
{ "document": { "aggregate_severity": { "namespace": "https://access.redhat.com/security/updates/classification/", "text": "Moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright \u00a9 Red Hat, Inc. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "An update for docker is now available for Red Hat Enterprise Linux 7 Extras.\n\nRed Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.", "title": "Topic" }, { "category": "general", "text": "Docker is an open-source engine that automates the deployment of any application as a lightweight, portable, self-sufficient container that will run virtually anywhere.\n\nSecurity Fix(es):\n\n* It was found that Docker would launch containers under the specified UID instead of a username. An attacker able to launch a container could use this flaw to escalate their privileges to root within the launched container. (CVE-2016-3697)\n\nThis issue was discovered by Mrunal Patel (Red Hat).\n\nBug Fix(es):\n\n* The process of pulling an image spawns a new \"goroutine\" for each layer in the image manifest. If any of these downloads, everything stops and an error is returned, even though other goroutines would still be running and writing output through a progress reader which is attached to an http response writer. Since the request handler had already returned from the first error, the http server panics when one of these download goroutines makes a write to the response writer buffer. This bug has been fixed, and docker no longer panics when pulling an image. (BZ#1264562)\n\n* Previously, in certain situations, a container rootfs remained busy during container removal. This typically happened if a container mount point leaked into another mount namespace. As a consequence, container removal failed. To fix this bug, a new docker daemon option \"dm.use_deferred_deletion\" has been provided. If set to true, this option will defer the container rootfs deletion. The user will see success on container removal but the actual thin device backing the rootfs will be deleted later when it is not busy anymore. (BZ#1190492)\n \t\n* Previously, the Docker unit file had the \"Restart\" option set to \"on-failure\". Consequently, the docker daemon was forced to restart even in cases where it couldn\u0027t be started because of configuration or other issues and this situation forced unnecessary restarts of the docker-storage-setup service in a loop. This also caused real error messages to be lost due to so many restarts. To fix this bug, \"Restart=on-failure\" has been replaced with \"Restart=on-abnormal\" in the docker unit file. As a result, the docker daemon will not automatically restart if it fails with an unclean exit code. (BZ#1319783)\n\n* Previously, the request body was incorrectly read twice by the docker daemon and consequently, an EOF error was returned. To fix this bug, the code which incorrectly read the request body the first time has been removed. As a result, the EOF error is no longer returned and the body is correctly read when really needed. (BZ#1329743)\n\nEnhancement(s):\n\n* The /usr/bin/docker script now calls /usr/bin/docker-current or /usr/bin/docker-latest based on the value of the sysconfig variable DOCKERBINARY present in /etc/sysconfig/docker. /usr/bin/docker and /etc/sysconfig/docker provided by the docker-common package allow the admin to configure which docker client binary gets called. /usr/bin/docker will call /usr/bin/docker-latest by default when docker is not installed. If docker is installed, /usr/bin/docker will call /usr/bin/docker-current by default, unless DOCKERBINARY is set to /usr/bin/docker-latest in /etc/sysconfig/docker. This way, you can use docker-latest or docker without the need to check which version of the daemon is currently running. (BZ#1328219)", "title": "Details" }, { "category": "legal_disclaimer", "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.", "title": "Terms of Use" } ], "publisher": { "category": "vendor", "contact_details": "https://access.redhat.com/security/team/contact/", "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.", "name": "Red Hat Product Security", "namespace": "https://www.redhat.com" }, "references": [ { "category": "self", "summary": "https://access.redhat.com/errata/RHSA-2016:1034", "url": "https://access.redhat.com/errata/RHSA-2016:1034" }, { "category": "external", "summary": "https://access.redhat.com/security/updates/classification/#moderate", "url": "https://access.redhat.com/security/updates/classification/#moderate" }, { "category": "external", "summary": "1186066", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1186066" }, { "category": "external", "summary": "1261565", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1261565" }, { "category": "external", "summary": "1266307", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1266307" }, { "category": "external", "summary": "1268059", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1268059" }, { "category": "external", "summary": "1272143", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1272143" }, { "category": "external", "summary": "1303110", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1303110" }, { "category": "external", "summary": "1309739", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1309739" }, { "category": "external", "summary": "1316651", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1316651" }, { "category": "external", "summary": "1319783", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1319783" }, { "category": "external", "summary": "1322762", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1322762" }, { "category": "external", "summary": "1328219", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1328219" }, { "category": "external", "summary": "1329423", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1329423" }, { "category": "external", "summary": "1329450", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1329450" }, { "category": "external", "summary": "1329743", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1329743" }, { "category": "external", "summary": "1330595", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1330595" }, { "category": "external", "summary": "1330622", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1330622" }, { "category": "external", "summary": "1331007", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1331007" }, { "category": "external", "summary": "1332592", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1332592" }, { "category": "self", "summary": "Canonical URL", "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2016/rhsa-2016_1034.json" } ], "title": "Red Hat Security Advisory: docker security, bug fix, and enhancement update", "tracking": { "current_release_date": "2024-11-22T10:01:45+00:00", "generator": { "date": "2024-11-22T10:01:45+00:00", "engine": { "name": "Red Hat SDEngine", "version": "4.2.1" } }, "id": "RHSA-2016:1034", "initial_release_date": "2016-05-12T15:15:01+00:00", "revision_history": [ { "date": "2016-05-12T15:15:01+00:00", "number": "1", "summary": "Initial version" }, { "date": "2016-05-12T15:15:01+00:00", "number": "2", "summary": "Last updated version" }, { "date": "2024-11-22T10:01:45+00:00", "number": "3", "summary": "Last generated version" } ], "status": "final", "version": "3" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_name", "name": "Red Hat Enterprise Linux 7 Extras", "product": { "name": "Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS", "product_identification_helper": { "cpe": "cpe:/a:redhat:rhel_extras_other:7" } } } ], "category": "product_family", "name": "Red Hat Enterprise Linux Extras" }, { "branches": [ { "category": "product_version", "name": "docker-logrotate-0:1.9.1-40.el7.x86_64", "product": { "name": "docker-logrotate-0:1.9.1-40.el7.x86_64", "product_id": "docker-logrotate-0:1.9.1-40.el7.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker-logrotate@1.9.1-40.el7?arch=x86_64" } } }, { "category": "product_version", "name": "docker-selinux-0:1.9.1-40.el7.x86_64", "product": { "name": "docker-selinux-0:1.9.1-40.el7.x86_64", "product_id": "docker-selinux-0:1.9.1-40.el7.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker-selinux@1.9.1-40.el7?arch=x86_64" } } }, { "category": "product_version", "name": "docker-0:1.9.1-40.el7.x86_64", "product": { "name": "docker-0:1.9.1-40.el7.x86_64", "product_id": "docker-0:1.9.1-40.el7.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker@1.9.1-40.el7?arch=x86_64" } } }, { "category": "product_version", "name": "docker-forward-journald-0:1.9.1-40.el7.x86_64", "product": { "name": "docker-forward-journald-0:1.9.1-40.el7.x86_64", "product_id": "docker-forward-journald-0:1.9.1-40.el7.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker-forward-journald@1.9.1-40.el7?arch=x86_64" } } }, { "category": "product_version", "name": "docker-common-0:1.9.1-40.el7.x86_64", "product": { "name": "docker-common-0:1.9.1-40.el7.x86_64", "product_id": "docker-common-0:1.9.1-40.el7.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker-common@1.9.1-40.el7?arch=x86_64" } } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_version", "name": "docker-0:1.9.1-40.el7.src", "product": { "name": "docker-0:1.9.1-40.el7.src", "product_id": "docker-0:1.9.1-40.el7.src", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker@1.9.1-40.el7?arch=src" } } } ], "category": "architecture", "name": "src" } ], "category": "vendor", "name": "Red Hat" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "docker-0:1.9.1-40.el7.src as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-0:1.9.1-40.el7.src" }, "product_reference": "docker-0:1.9.1-40.el7.src", "relates_to_product_reference": "7Server-EXTRAS" }, { "category": "default_component_of", "full_product_name": { "name": "docker-0:1.9.1-40.el7.x86_64 as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-0:1.9.1-40.el7.x86_64" }, "product_reference": "docker-0:1.9.1-40.el7.x86_64", "relates_to_product_reference": "7Server-EXTRAS" }, { "category": "default_component_of", "full_product_name": { "name": "docker-common-0:1.9.1-40.el7.x86_64 as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-common-0:1.9.1-40.el7.x86_64" }, "product_reference": "docker-common-0:1.9.1-40.el7.x86_64", "relates_to_product_reference": "7Server-EXTRAS" }, { "category": "default_component_of", "full_product_name": { "name": "docker-forward-journald-0:1.9.1-40.el7.x86_64 as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-forward-journald-0:1.9.1-40.el7.x86_64" }, "product_reference": "docker-forward-journald-0:1.9.1-40.el7.x86_64", "relates_to_product_reference": "7Server-EXTRAS" }, { "category": "default_component_of", "full_product_name": { "name": "docker-logrotate-0:1.9.1-40.el7.x86_64 as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-logrotate-0:1.9.1-40.el7.x86_64" }, "product_reference": "docker-logrotate-0:1.9.1-40.el7.x86_64", "relates_to_product_reference": "7Server-EXTRAS" }, { "category": "default_component_of", "full_product_name": { "name": "docker-selinux-0:1.9.1-40.el7.x86_64 as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-selinux-0:1.9.1-40.el7.x86_64" }, "product_reference": "docker-selinux-0:1.9.1-40.el7.x86_64", "relates_to_product_reference": "7Server-EXTRAS" } ] }, "vulnerabilities": [ { "acknowledgments": [ { "names": [ "Mrunal Patel" ], "organization": "Red Hat", "summary": "This issue was discovered by Red Hat." } ], "cve": "CVE-2016-3697", "discovery_date": "2016-04-19T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1329450" } ], "notes": [ { "category": "description", "text": "It was found that Docker would launch containers under the specified UID instead of a username. An attacker able to launch a container could use this flaw to escalate their privileges to root within the launched container.", "title": "Vulnerability description" }, { "category": "summary", "text": "docker: privilege escalation via confusion of usernames and UIDs", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "7Server-EXTRAS:docker-0:1.9.1-40.el7.src", "7Server-EXTRAS:docker-0:1.9.1-40.el7.x86_64", "7Server-EXTRAS:docker-common-0:1.9.1-40.el7.x86_64", "7Server-EXTRAS:docker-forward-journald-0:1.9.1-40.el7.x86_64", "7Server-EXTRAS:docker-logrotate-0:1.9.1-40.el7.x86_64", "7Server-EXTRAS:docker-selinux-0:1.9.1-40.el7.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2016-3697" }, { "category": "external", "summary": "RHBZ#1329450", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1329450" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2016-3697", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3697" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2016-3697", "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-3697" } ], "release_date": "2016-04-22T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2016-05-12T15:15:01+00:00", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258", "product_ids": [ "7Server-EXTRAS:docker-0:1.9.1-40.el7.src", "7Server-EXTRAS:docker-0:1.9.1-40.el7.x86_64", "7Server-EXTRAS:docker-common-0:1.9.1-40.el7.x86_64", "7Server-EXTRAS:docker-forward-journald-0:1.9.1-40.el7.x86_64", "7Server-EXTRAS:docker-logrotate-0:1.9.1-40.el7.x86_64", "7Server-EXTRAS:docker-selinux-0:1.9.1-40.el7.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2016:1034" } ], "scores": [ { "cvss_v2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "PARTIAL", "baseScore": 6.0, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P", "version": "2.0" }, "products": [ "7Server-EXTRAS:docker-0:1.9.1-40.el7.src", "7Server-EXTRAS:docker-0:1.9.1-40.el7.x86_64", "7Server-EXTRAS:docker-common-0:1.9.1-40.el7.x86_64", "7Server-EXTRAS:docker-forward-journald-0:1.9.1-40.el7.x86_64", "7Server-EXTRAS:docker-logrotate-0:1.9.1-40.el7.x86_64", "7Server-EXTRAS:docker-selinux-0:1.9.1-40.el7.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "docker: privilege escalation via confusion of usernames and UIDs" } ] }
rhsa-2016:2634
Vulnerability from csaf_redhat
Published
2016-11-03 16:51
Modified
2025-03-19 14:15
Summary
Red Hat Security Advisory: docker security and bug fix update
Notes
Topic
An update for docker is now available for Red Hat Enterprise Linux 7 Extras.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Details
Docker is an open-source engine that automates the deployment of any application as a lightweight, portable, self-sufficient container that will run virtually anywhere.
Security Fix(es):
* It was found that Docker would launch containers under the specified UID instead of a username. An attacker able to launch a container could use this flaw to escalate their privileges to root within the launched container. (CVE-2016-3697)
This issue was discovered by Mrunal Patel (Red Hat).
Bug Fix(es):
* This update also provides various bug fixes and enhancements. Users are advised to upgrade to these updated packages.
Terms of Use
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
{ "document": { "aggregate_severity": { "namespace": "https://access.redhat.com/security/updates/classification/", "text": "Moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright \u00a9 Red Hat, Inc. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "An update for docker is now available for Red Hat Enterprise Linux 7 Extras.\n\nRed Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.", "title": "Topic" }, { "category": "general", "text": "Docker is an open-source engine that automates the deployment of any application as a lightweight, portable, self-sufficient container that will run virtually anywhere.\n\nSecurity Fix(es):\n\n* It was found that Docker would launch containers under the specified UID instead of a username. An attacker able to launch a container could use this flaw to escalate their privileges to root within the launched container. (CVE-2016-3697)\n\nThis issue was discovered by Mrunal Patel (Red Hat).\n\nBug Fix(es):\n\n* This update also provides various bug fixes and enhancements. Users are advised to upgrade to these updated packages.", "title": "Details" }, { "category": "legal_disclaimer", "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.", "title": "Terms of Use" } ], "publisher": { "category": "vendor", "contact_details": "https://access.redhat.com/security/team/contact/", "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.", "name": "Red Hat Product Security", "namespace": "https://www.redhat.com" }, "references": [ { "category": "self", "summary": "https://access.redhat.com/errata/RHSA-2016:2634", "url": "https://access.redhat.com/errata/RHSA-2016:2634" }, { "category": "external", "summary": "https://access.redhat.com/security/updates/classification/#moderate", "url": "https://access.redhat.com/security/updates/classification/#moderate" }, { "category": "external", "summary": "1303123", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1303123" }, { "category": "external", "summary": "1329450", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1329450" }, { "category": "external", "summary": "1330141", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1330141" }, { "category": "external", "summary": "1335951", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1335951" }, { "category": "external", "summary": "1336857", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1336857" }, { "category": "external", "summary": "1346185", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1346185" }, { "category": "external", "summary": "1357121", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1357121" }, { "category": "external", "summary": "1358819", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1358819" }, { "category": "external", "summary": "1362611", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1362611" }, { "category": "external", "summary": "1370935", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1370935" }, { "category": "external", "summary": "1374265", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1374265" }, { "category": "external", "summary": "1385641", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1385641" }, { "category": "self", "summary": "Canonical URL", "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2016/rhsa-2016_2634.json" } ], "title": "Red Hat Security Advisory: docker security and bug fix update", "tracking": { "current_release_date": "2025-03-19T14:15:34+00:00", "generator": { "date": "2025-03-19T14:15:34+00:00", "engine": { "name": "Red Hat SDEngine", "version": "4.4.1" } }, "id": "RHSA-2016:2634", "initial_release_date": "2016-11-03T16:51:48+00:00", "revision_history": [ { "date": "2016-11-03T16:51:48+00:00", "number": "1", "summary": "Initial version" }, { "date": "2016-11-03T16:51:48+00:00", "number": "2", "summary": "Last updated version" }, { "date": "2025-03-19T14:15:34+00:00", "number": "3", "summary": "Last generated version" } ], "status": "final", "version": "3" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_name", "name": "Red Hat Enterprise Linux 7 Extras", "product": { "name": "Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS", "product_identification_helper": { "cpe": "cpe:/a:redhat:rhel_extras_other:7" } } } ], "category": "product_family", "name": "Red Hat Enterprise Linux Extras" }, { "branches": [ { "category": "product_version", "name": "docker-common-0:1.10.3-57.el7.x86_64", "product": { "name": "docker-common-0:1.10.3-57.el7.x86_64", "product_id": "docker-common-0:1.10.3-57.el7.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker-common@1.10.3-57.el7?arch=x86_64" } } }, { "category": "product_version", "name": "docker-logrotate-0:1.10.3-57.el7.x86_64", "product": { "name": "docker-logrotate-0:1.10.3-57.el7.x86_64", "product_id": "docker-logrotate-0:1.10.3-57.el7.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker-logrotate@1.10.3-57.el7?arch=x86_64" } } }, { "category": "product_version", "name": "docker-selinux-0:1.10.3-57.el7.x86_64", "product": { "name": "docker-selinux-0:1.10.3-57.el7.x86_64", "product_id": "docker-selinux-0:1.10.3-57.el7.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker-selinux@1.10.3-57.el7?arch=x86_64" } } }, { "category": "product_version", "name": "docker-rhel-push-plugin-0:1.10.3-57.el7.x86_64", "product": { "name": "docker-rhel-push-plugin-0:1.10.3-57.el7.x86_64", "product_id": "docker-rhel-push-plugin-0:1.10.3-57.el7.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker-rhel-push-plugin@1.10.3-57.el7?arch=x86_64" } } }, { "category": "product_version", "name": "docker-v1.10-migrator-0:1.10.3-57.el7.x86_64", "product": { "name": "docker-v1.10-migrator-0:1.10.3-57.el7.x86_64", "product_id": "docker-v1.10-migrator-0:1.10.3-57.el7.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker-v1.10-migrator@1.10.3-57.el7?arch=x86_64" } } }, { "category": "product_version", "name": "docker-lvm-plugin-0:1.10.3-57.el7.x86_64", "product": { "name": "docker-lvm-plugin-0:1.10.3-57.el7.x86_64", "product_id": "docker-lvm-plugin-0:1.10.3-57.el7.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker-lvm-plugin@1.10.3-57.el7?arch=x86_64" } } }, { "category": "product_version", "name": "docker-novolume-plugin-0:1.10.3-57.el7.x86_64", "product": { "name": "docker-novolume-plugin-0:1.10.3-57.el7.x86_64", "product_id": "docker-novolume-plugin-0:1.10.3-57.el7.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker-novolume-plugin@1.10.3-57.el7?arch=x86_64" } } }, { "category": "product_version", "name": "docker-0:1.10.3-57.el7.x86_64", "product": { "name": "docker-0:1.10.3-57.el7.x86_64", "product_id": "docker-0:1.10.3-57.el7.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker@1.10.3-57.el7?arch=x86_64" } } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_version", "name": "docker-0:1.10.3-57.el7.src", "product": { "name": "docker-0:1.10.3-57.el7.src", "product_id": "docker-0:1.10.3-57.el7.src", "product_identification_helper": { "purl": "pkg:rpm/redhat/docker@1.10.3-57.el7?arch=src" } } } ], "category": "architecture", "name": "src" } ], "category": "vendor", "name": "Red Hat" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "docker-0:1.10.3-57.el7.src as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-0:1.10.3-57.el7.src" }, "product_reference": "docker-0:1.10.3-57.el7.src", "relates_to_product_reference": "7Server-EXTRAS" }, { "category": "default_component_of", "full_product_name": { "name": "docker-0:1.10.3-57.el7.x86_64 as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-0:1.10.3-57.el7.x86_64" }, "product_reference": "docker-0:1.10.3-57.el7.x86_64", "relates_to_product_reference": "7Server-EXTRAS" }, { "category": "default_component_of", "full_product_name": { "name": "docker-common-0:1.10.3-57.el7.x86_64 as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-common-0:1.10.3-57.el7.x86_64" }, "product_reference": "docker-common-0:1.10.3-57.el7.x86_64", "relates_to_product_reference": "7Server-EXTRAS" }, { "category": "default_component_of", "full_product_name": { "name": "docker-logrotate-0:1.10.3-57.el7.x86_64 as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-logrotate-0:1.10.3-57.el7.x86_64" }, "product_reference": "docker-logrotate-0:1.10.3-57.el7.x86_64", "relates_to_product_reference": "7Server-EXTRAS" }, { "category": "default_component_of", "full_product_name": { "name": "docker-lvm-plugin-0:1.10.3-57.el7.x86_64 as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-lvm-plugin-0:1.10.3-57.el7.x86_64" }, "product_reference": "docker-lvm-plugin-0:1.10.3-57.el7.x86_64", "relates_to_product_reference": "7Server-EXTRAS" }, { "category": "default_component_of", "full_product_name": { "name": "docker-novolume-plugin-0:1.10.3-57.el7.x86_64 as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-novolume-plugin-0:1.10.3-57.el7.x86_64" }, "product_reference": "docker-novolume-plugin-0:1.10.3-57.el7.x86_64", "relates_to_product_reference": "7Server-EXTRAS" }, { "category": "default_component_of", "full_product_name": { "name": "docker-rhel-push-plugin-0:1.10.3-57.el7.x86_64 as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-rhel-push-plugin-0:1.10.3-57.el7.x86_64" }, "product_reference": "docker-rhel-push-plugin-0:1.10.3-57.el7.x86_64", "relates_to_product_reference": "7Server-EXTRAS" }, { "category": "default_component_of", "full_product_name": { "name": "docker-selinux-0:1.10.3-57.el7.x86_64 as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-selinux-0:1.10.3-57.el7.x86_64" }, "product_reference": "docker-selinux-0:1.10.3-57.el7.x86_64", "relates_to_product_reference": "7Server-EXTRAS" }, { "category": "default_component_of", "full_product_name": { "name": "docker-v1.10-migrator-0:1.10.3-57.el7.x86_64 as a component of Red Hat Enterprise Linux 7 Extras", "product_id": "7Server-EXTRAS:docker-v1.10-migrator-0:1.10.3-57.el7.x86_64" }, "product_reference": "docker-v1.10-migrator-0:1.10.3-57.el7.x86_64", "relates_to_product_reference": "7Server-EXTRAS" } ] }, "vulnerabilities": [ { "acknowledgments": [ { "names": [ "Mrunal Patel" ], "organization": "Red Hat", "summary": "This issue was discovered by Red Hat." } ], "cve": "CVE-2016-3697", "discovery_date": "2016-04-19T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1329450" } ], "notes": [ { "category": "description", "text": "It was found that Docker would launch containers under the specified UID instead of a username. An attacker able to launch a container could use this flaw to escalate their privileges to root within the launched container.", "title": "Vulnerability description" }, { "category": "summary", "text": "docker: privilege escalation via confusion of usernames and UIDs", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "7Server-EXTRAS:docker-0:1.10.3-57.el7.src", "7Server-EXTRAS:docker-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-common-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-logrotate-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-lvm-plugin-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-novolume-plugin-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-rhel-push-plugin-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-selinux-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-v1.10-migrator-0:1.10.3-57.el7.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2016-3697" }, { "category": "external", "summary": "RHBZ#1329450", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1329450" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2016-3697", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3697" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2016-3697", "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-3697" } ], "release_date": "2016-04-22T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2016-11-03T16:51:48+00:00", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258", "product_ids": [ "7Server-EXTRAS:docker-0:1.10.3-57.el7.src", "7Server-EXTRAS:docker-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-common-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-logrotate-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-lvm-plugin-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-novolume-plugin-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-rhel-push-plugin-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-selinux-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-v1.10-migrator-0:1.10.3-57.el7.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2016:2634" } ], "scores": [ { "cvss_v2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "PARTIAL", "baseScore": 6.0, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P", "version": "2.0" }, "products": [ "7Server-EXTRAS:docker-0:1.10.3-57.el7.src", "7Server-EXTRAS:docker-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-common-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-logrotate-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-lvm-plugin-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-novolume-plugin-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-rhel-push-plugin-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-selinux-0:1.10.3-57.el7.x86_64", "7Server-EXTRAS:docker-v1.10-migrator-0:1.10.3-57.el7.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "docker: privilege escalation via confusion of usernames and UIDs" } ] }
gsd-2016-3697
Vulnerability from gsd
Modified
2023-12-13 01:21
Details
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
Aliases
Aliases
{ "GSD": { "alias": "CVE-2016-3697", "description": "libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.", "id": "GSD-2016-3697", "references": [ "https://www.suse.com/security/cve/CVE-2016-3697.html", "https://access.redhat.com/errata/RHSA-2016:2634", "https://access.redhat.com/errata/RHSA-2016:1034", "https://advisories.mageia.org/CVE-2016-3697.html", "https://linux.oracle.com/cve/CVE-2016-3697.html" ] }, "gsd": { "metadata": { "exploitCode": "unknown", "remediation": "unknown", "reportConfidence": "confirmed", "type": "vulnerability" }, "osvSchema": { "aliases": [ "CVE-2016-3697" ], "details": "libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.", "id": "GSD-2016-3697", "modified": "2023-12-13T01:21:27.852004Z", "schema_version": "1.4.0" } }, "namespaces": { "cve.org": { "CVE_data_meta": { "ASSIGNER": "secalert@redhat.com", "ID": "CVE-2016-3697", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_affected": "=", "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "http://lists.opensuse.org/opensuse-updates/2016-05/msg00111.html", "refsource": "MISC", "url": "http://lists.opensuse.org/opensuse-updates/2016-05/msg00111.html" }, { "name": "http://rhn.redhat.com/errata/RHSA-2016-1034.html", "refsource": "MISC", "url": "http://rhn.redhat.com/errata/RHSA-2016-1034.html" }, { "name": "http://rhn.redhat.com/errata/RHSA-2016-2634.html", "refsource": "MISC", "url": "http://rhn.redhat.com/errata/RHSA-2016-2634.html" }, { "name": "https://github.com/docker/docker/issues/21436", "refsource": "MISC", "url": "https://github.com/docker/docker/issues/21436" }, { "name": "https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091", "refsource": "MISC", "url": "https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091" }, { "name": "https://github.com/opencontainers/runc/pull/708", "refsource": "MISC", "url": "https://github.com/opencontainers/runc/pull/708" }, { "name": "https://github.com/opencontainers/runc/releases/tag/v0.1.0", "refsource": "MISC", "url": "https://github.com/opencontainers/runc/releases/tag/v0.1.0" }, { "name": "https://security.gentoo.org/glsa/201612-28", "refsource": "MISC", "url": "https://security.gentoo.org/glsa/201612-28" } ] } }, "gitlab.com": { "advisories": [ { "affected_range": "\u003c0.1.0", "affected_versions": "All versions before 0.1.0", "cvss_v2": "AV:L/AC:L/Au:N/C:P/I:N/A:N", "cvss_v3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwe_ids": [ "CWE-1035", "CWE-264", "CWE-937" ], "date": "2021-12-20", "description": "libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.", "fixed_versions": [ "0.1.0" ], "identifier": "CVE-2016-3697", "identifiers": [ "GHSA-q3j5-32m5-58c2", "CVE-2016-3697" ], "not_impacted": "All versions starting from 0.1.0", "package_slug": "go/github.com/opencontainers/runc", "pubdate": "2021-12-20", "solution": "Upgrade to version 0.1.0 or above.", "title": "Privilege Elevation in runc", "urls": [ "https://nvd.nist.gov/vuln/detail/CVE-2016-3697", "https://github.com/docker/docker/issues/21436", "https://github.com/opencontainers/runc/pull/708", "https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091", "https://github.com/opencontainers/runc/releases/tag/v0.1.0", "https://lists.opensuse.org/opensuse-updates/2016-05/msg00111.html", "https://rhn.redhat.com/errata/RHSA-2016-1034.html", "https://rhn.redhat.com/errata/RHSA-2016-2634.html", "https://security.gentoo.org/glsa/201612-28", "https://github.com/advisories/GHSA-q3j5-32m5-58c2" ], "uuid": "c742d8bf-ef7b-4732-bfe2-e929a588d092" } ] }, "nvd.nist.gov": { "configurations": { "CVE_data_version": "4.0", "nodes": [ { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndIncluding": "1.11.1", "vulnerable": true } ], "operator": "OR" }, { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndIncluding": "0.0.9", "vulnerable": true } ], "operator": "OR" }, { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true } ], "operator": "OR" } ] }, "cve": { "CVE_data_meta": { "ASSIGNER": "secalert@redhat.com", "ID": "CVE-2016-3697" }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "en", "value": "libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "en", "value": "CWE-264" } ] } ] }, "references": { "reference_data": [ { "name": "https://github.com/opencontainers/runc/pull/708", "refsource": "CONFIRM", "tags": [ "Third Party Advisory" ], "url": "https://github.com/opencontainers/runc/pull/708" }, { "name": "https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091", "refsource": "CONFIRM", "tags": [ "Third Party Advisory" ], "url": "https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091" }, { "name": "openSUSE-SU-2016:1417", "refsource": "SUSE", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://lists.opensuse.org/opensuse-updates/2016-05/msg00111.html" }, { "name": "https://github.com/docker/docker/issues/21436", "refsource": "CONFIRM", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/docker/docker/issues/21436" }, { "name": "RHSA-2016:1034", "refsource": "REDHAT", "tags": [ "Third Party Advisory" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-1034.html" }, { "name": "https://github.com/opencontainers/runc/releases/tag/v0.1.0", "refsource": "CONFIRM", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/opencontainers/runc/releases/tag/v0.1.0" }, { "name": "RHSA-2016:2634", "refsource": "REDHAT", "tags": [ "Third Party Advisory" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-2634.html" }, { "name": "GLSA-201612-28", "refsource": "GENTOO", "tags": [ "Third Party Advisory" ], "url": "https://security.gentoo.org/glsa/201612-28" } ] } }, "impact": { "baseMetricV2": { "cvssV2": { "accessComplexity": "LOW", "accessVector": "LOCAL", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 2.1, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N", "version": "2.0" }, "exploitabilityScore": 3.9, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "severity": "LOW", "userInteractionRequired": false }, "baseMetricV3": { "cvssV3": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9 } }, "lastModifiedDate": "2021-01-05T17:38Z", "publishedDate": "2016-06-01T20:59Z" } } }
ghsa-q3j5-32m5-58c2
Vulnerability from github
Published
2021-12-20 18:21
Modified
2024-05-20 19:40
Severity ?
VLAI Severity ?
Summary
Privilege Elevation in runc
Details
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
{ "affected": [ { "package": { "ecosystem": "Go", "name": "github.com/opencontainers/runc" }, "ranges": [ { "events": [ { "introduced": "0" }, { "fixed": "0.1.0" } ], "type": "ECOSYSTEM" } ] } ], "aliases": [ "CVE-2016-3697" ], "database_specific": { "cwe_ids": [ "CWE-269" ], "github_reviewed": true, "github_reviewed_at": "2021-05-20T18:53:49Z", "nvd_published_at": null, "severity": "HIGH" }, "details": "libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.", "id": "GHSA-q3j5-32m5-58c2", "modified": "2024-05-20T19:40:50Z", "published": "2021-12-20T18:21:34Z", "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-3697" }, { "type": "WEB", "url": "https://github.com/docker/docker/issues/21436" }, { "type": "WEB", "url": "https://github.com/opencontainers/runc/pull/708" }, { "type": "WEB", "url": "https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091" }, { "type": "PACKAGE", "url": "https://github.com/opencontainers/runc" }, { "type": "WEB", "url": "https://github.com/opencontainers/runc/releases/tag/v0.1.0" }, { "type": "WEB", "url": "https://lists.opensuse.org/opensuse-updates/2016-05/msg00111.html" }, { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2021-0070" }, { "type": "WEB", "url": "https://rhn.redhat.com/errata/RHSA-2016-1034.html" }, { "type": "WEB", "url": "https://rhn.redhat.com/errata/RHSA-2016-2634.html" }, { "type": "WEB", "url": "https://security.gentoo.org/glsa/201612-28" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2016-1034.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2016-2634.html" } ], "schema_version": "1.4.0", "severity": [ { "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "type": "CVSS_V3" } ], "summary": "Privilege Elevation in runc" }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…