Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-20699

Опубликовано: 04 окт. 2018
Источник: redhat
CVSS3: 4.5

Описание

Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.

Отчет

This issue affects the versions of docker as shipped with Red Hat Enterprise Linux 7, however if docker is accessible only by root or highly privileged users, as it is by default, a low-privileged attacker will not be able to trigger the flaw.

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1666565docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
около 7 лет назад

Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.

CVSS3: 4.9
nvd
около 7 лет назад

Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.

CVSS3: 4.9
debian
около 7 лет назад

Docker Engine before 18.09 allows attackers to cause a denial of servi ...

CVSS3: 4.9
github
больше 3 лет назад

Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.

oracle-oval
почти 7 лет назад

ELSA-2019-4597: docker-engine security update (IMPORTANT)

4.5 Medium

CVSS3