Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-11468

Опубликовано: 07 июл. 2017
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.

It was found that docker-distribution did not properly restrict memory allocation size for a registry instance through the manifest endpoint. An attacker could send a specially crafted request that would exhaust the memory of the docker-distribution service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7kubernetesNot affected
Red Hat Enterprise Linux 7 Extrasdocker-distributionFixedRHSA-2017:260305.09.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=1474893docker-distribution: Does not properly restrict the amount of content accepted from a user

EPSS

Процентиль: 63%
0.00442
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.

CVSS3: 7.5
nvd
больше 8 лет назад

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.

CVSS3: 7.5
debian
больше 8 лет назад

Docker Registry before 2.6.2 in Docker Distribution does not properly ...

suse-cvrf
почти 8 лет назад

Security update for docker-distribution

suse-cvrf
почти 8 лет назад

Security update for docker-distribution

EPSS

Процентиль: 63%
0.00442
Низкий

5.3 Medium

CVSS3