Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6fj5-m822-rqx8

Опубликовано: 31 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

moby docker daemon crash during image pull of malicious image

Impact

Pulling an intentionally malformed Docker image manifest crashes the dockerd daemon.

Patches

Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.

Credits

Maintainers would like to thank Josh Larsen, Ian Coldwater, Duffie Cooley, Rory McCune for working on the vulnerability and Brad Geesaman for responsibly disclosing it to security@docker.com.

Пакеты

Наименование

github.com/moby/moby

go
Затронутые версииВерсия исправления

< 19.3.15

19.3.15

Наименование

github.com/moby/moby

go
Затронутые версииВерсия исправления

>= 20.10.0-beta1, < 20.10.3

20.10.3

EPSS

Процентиль: 78%
0.01168
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400
CWE-754

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 5 лет назад

In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.

CVSS3: 6.5
redhat
около 5 лет назад

In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.

CVSS3: 6.5
nvd
около 5 лет назад

In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.

CVSS3: 6.5
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 6.5
debian
около 5 лет назад

In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in ...

EPSS

Процентиль: 78%
0.01168
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400
CWE-754