Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-16539

Опубликовано: 04 нояб. 2017
Источник: nvd
CVSS3: 5.9
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:*
Версия до 17.03.2 (включая)

EPSS

Процентиль: 73%
0.00771
Низкий

5.9 Medium

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-200
CWE-200

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 8 лет назад

The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.

CVSS3: 7.5
redhat
больше 8 лет назад

The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.

CVSS3: 5.9
debian
больше 8 лет назад

The DefaultLinuxSpec function in oci/defaults.go in Docker Moby throug ...

CVSS3: 5.9
github
больше 3 лет назад

Docker Moby /proc/scsi Path Exposure Allows Host Data Loss (SCSI MICDROP)

suse-cvrf
почти 8 лет назад

Security update for docker, docker-runc, containerd, golang-github-docker-libnetwork

EPSS

Процентиль: 73%
0.00771
Низкий

5.9 Medium

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-200
CWE-200