Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10892

Опубликовано: 06 июл. 2018
Источник: debian

Описание

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
docker.iofixed18.06.0+dfsg1-1experimentalpackage
docker.iofixed18.06.1+dfsg1-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1598581

  • https://github.com/moby/moby/pull/37404

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

CVSS3: 6.3
redhat
больше 7 лет назад

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

CVSS3: 5.3
nvd
больше 7 лет назад

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

CVSS3: 5.3
github
больше 3 лет назад

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

suse-cvrf
больше 6 лет назад

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork