Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g44j-7vp3-68cv

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.4

Описание

Arbitrary File Write in Libcontainer

Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.

Пакеты

Наименование

github.com/docker/docker

go
Затронутые версииВерсия исправления

>= 1.6.0, < 1.6.1

1.6.1

EPSS

Процентиль: 19%
0.0006
Низкий

8.4 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 10 лет назад

Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.

redhat
около 10 лет назад

Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.

CVSS3: 7.8
nvd
около 10 лет назад

Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.

CVSS3: 7.8
debian
около 10 лет назад

Libcontainer 1.6.0, as used in Docker Engine, allows local users to es ...

oracle-oval
около 10 лет назад

ELSA-2015-3037: docker security update (IMPORTANT)

EPSS

Процентиль: 19%
0.0006
Низкий

8.4 High

CVSS3

Дефекты

CWE-59