Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2014-3095

Опубликовано: 05 дек. 2014
Источник: oracle-oval
Платформа: Oracle Linux 6
Платформа: Oracle Linux 7

Описание

ELSA-2014-3095: docker security and bug fix update (IMPORTANT)

[1.3.2-1.0.1]

  • Rename requirement of docker-io-pkg-devel in %package devel as docker-pkg-devel
  • Restore SysV init scripts for Oracle Linux 6
  • Require Oracle Unbreakable Enterprise Kernel Release 3 or higher
  • Rename as docker.
  • Re-enable btrfs graphdriver support

[1.3.2-1]

  • Update source to 1.3.2 from https://github.com/docker/docker/releases/tag/v1.3.2 Prevent host privilege escalation from an image extraction vulnerability (CVE-2014-6407). Prevent container escalation from malicious security options applied to images (CVE-2014-6408). The '--insecure-registry' flag of the 'docker run' command has undergone several refinements and additions. You can now specify a sub-net in order to set a range of registries which the Docker daemon will consider insecure. By default, Docker now defines 'localhost' as an insecure registry. Registries can now be referenced using the Classless Inter-Domain Routing (CIDR) format. When mirroring is enabled, the experimental registry v2 API is skipped.

[1.3.1-2]

  • Remove pandoc from build reqs

[1.3.1-1]

  • update to v1.3.1

[1.3.0-1]

  • Resolves: rhbz#1153936 - update to v1.3.0
  • iptables=false => ip-masq=false

[1.2.0-3]

  • Resolves: rhbz#1139415 - correct path for bash completion /usr/share/bash-completion/completions
  • sysvinit script update as per upstream commit 640d2ef6f54d96ac4fc3f0f745cb1e6a35148607
  • dont own dirs for vim highlighting, bash completion and udev

[1.2.0-2]

[1.2.0-1]

  • Resolves: rhbz#1132824 - update to v1.2.0

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

docker

1.3.2-1.0.1.el6

docker-devel

1.3.2-1.0.1.el6

docker-pkg-devel

1.3.2-1.0.1.el6

Oracle Linux 7

Oracle Linux x86_64

docker

1.3.2-1.0.1.el7

docker-devel

1.3.2-1.0.1.el7

docker-pkg-devel

1.3.2-1.0.1.el7

Связанные CVE

Связанные уязвимости

ubuntu
больше 10 лет назад

Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applying unspecified security options to an image.

redhat
больше 10 лет назад

Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applying unspecified security options to an image.

nvd
больше 10 лет назад

Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applying unspecified security options to an image.

debian
больше 10 лет назад

Docker 1.3.0 through 1.3.1 allows remote attackers to modify the defau ...

ubuntu
больше 10 лет назад

Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.