Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3627

Опубликовано: 07 мая 2015
Источник: redhat
CVSS2: 4.3

Описание

Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1219061docker: insecure opening of file-descriptor 1 leading to privilege escalation

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.

nvd
около 10 лет назад

Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.

msrc
почти 4 года назад

Описание отсутствует

debian
около 10 лет назад

Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor ...

github
больше 3 лет назад

Symlink Attack in Libcontainer and Docker Engine

4.3 Medium

CVSS2