Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-15112

Опубликовано: 29 июн. 2021
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2021-15112: docker-engine docker-cli security update (IMPORTANT)

docker-engine [19.03.11-11]

  • Addresses CVE-2021-30465 - updated runc minimum version to runc >= 3:1.0.0-1.rc95.

[19.03.11-10]

  • Addresses runc CVE-2021-30465 - updated runc versions in cli/vendor.conf and docker-engine/vendor.conf to 1.0.0-rc95.

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

docker-cli

19.03.11.ol-11.el7

docker-engine

19.03.11.ol-11.el7

Oracle Linux x86_64

docker-cli

19.03.11.ol-11.el7

docker-engine

19.03.11.ol-11.el7

Связанные CVE

Связанные уязвимости

CVSS3: 8.5
ubuntu
около 4 лет назад

runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition.

CVSS3: 7.5
redhat
около 4 лет назад

runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition.

CVSS3: 8.5
nvd
около 4 лет назад

runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition.

CVSS3: 8.5
debian
около 4 лет назад

runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Dire ...

suse-cvrf
около 4 лет назад

Security update for runc