Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-16539

Опубликовано: 04 нояб. 2017
Источник: debian
EPSS Низкий

Описание

The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
docker.iofixed1.13.1~ds3-1package

Примечания

  • https://github.com/moby/moby/pull/35399

  • https://github.com/moby/moby/pull/35399/commits/a21ecdf3c8a343a7c94e4c4d01b178c87ca7aaa1

EPSS

Процентиль: 73%
0.00771
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 8 лет назад

The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.

CVSS3: 7.5
redhat
больше 8 лет назад

The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.

CVSS3: 5.9
nvd
больше 8 лет назад

The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.

CVSS3: 5.9
github
больше 3 лет назад

Docker Moby /proc/scsi Path Exposure Allows Host Data Loss (SCSI MICDROP)

suse-cvrf
почти 8 лет назад

Security update for docker, docker-runc, containerd, golang-github-docker-libnetwork

EPSS

Процентиль: 73%
0.00771
Низкий