Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3697

Опубликовано: 22 апр. 2016
Источник: redhat
CVSS2: 6
EPSS Низкий

Описание

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.

It was found that Docker would launch containers under the specified UID instead of a username. An attacker able to launch a container could use this flaw to escalate their privileges to root within the launched container.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Enterprise 3SecurityAffected
Red Hat Enterprise Linux 7 ExtrasdockerFixedRHSA-2016:103412.05.2016
Red Hat Enterprise Linux 7 ExtrasdockerFixedRHSA-2016:263403.11.2016

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1329450docker: privilege escalation via confusion of usernames and UIDs

EPSS

Процентиль: 28%
0.00098
Низкий

6 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 9 лет назад

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.

CVSS3: 7.8
nvd
около 9 лет назад

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.

CVSS3: 7.8
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 7.8
debian
около 9 лет назад

libcontainer/user/user.go in runC before 0.1.0, as used in Docker befo ...

suse-cvrf
около 9 лет назад

Security update for docker

EPSS

Процентиль: 28%
0.00098
Низкий

6 Medium

CVSS2

Уязвимость CVE-2016-3697