Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-19921

Опубликовано: 12 фев. 2020
Источник: debian
EPSS Низкий

Описание

runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)

Пакеты

ПакетСтатусВерсия исправленияРелизТип
runcfixed1.0.0~rc10+dfsg1-1package
runcno-dsastretchpackage

Примечания

  • https://github.com/opencontainers/runc/issues/2197

  • https://github.com/opencontainers/runc/pull/2190

  • https://github.com/opencontainers/runc/commit/3291d66b98445bd7f7d02eac7f2bca2ac2c56942 (v1.0.0-rc10)

EPSS

Процентиль: 48%
0.00244
Низкий

Связанные уязвимости

CVSS3: 7
ubuntu
больше 5 лет назад

runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)

CVSS3: 7
redhat
больше 5 лет назад

runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)

CVSS3: 7
nvd
больше 5 лет назад

runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)

suse-cvrf
больше 5 лет назад

Security update for docker-runc

suse-cvrf
около 5 лет назад

Security update for runc

EPSS

Процентиль: 48%
0.00244
Низкий