Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-4827

Опубликовано: 05 дек. 2019
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2019-4827: docker-engine docker-cli security update (IMPORTANT)

docker-engine [19.03.1-1.0.0]

  • update to 19.03.1

[19.03-0.0.1]

  • update to 19.03

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

docker-cli

19.03.1.ol-1.0.0.el7

docker-engine

19.03.1.ol-1.0.0.el7

Oracle Linux x86_64

docker-cli

19.03.1.ol-1.0.0.el7

docker-engine

19.03.1.ol-1.0.0.el7

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.

CVSS3: 8.3
redhat
около 6 лет назад

In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.

CVSS3: 9.8
nvd
около 6 лет назад

In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.

CVSS3: 9.8
debian
около 6 лет назад

In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka ...

CVSS3: 7.5
ubuntu
больше 6 лет назад

In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen filesystem (or from within a chroot).