Описание
Security update for docker
docker was updated to version 1.8.3 to fix two security issues.
These security issues were fixed:
- CVE-2014-8178: Manipulated layer IDs could have lead to local graph poisoning (bsc#949660).
- CVE-2014-8179: Manifest validation and parsing logic errors allowed pull-by-digest validation bypass (bsc#949660).
This non-security issues was fixed:
- Add
--disable-legacy-registry
to prevent a daemon from using a v1 registry
More information about docker 1.8.3 can be found at https://blog.docker.com/2015/10/security-release-docker-1-8-3-1-6-2-cs7/
Список пакетов
SUSE Linux Enterprise Module for Containers 12
Ссылки
- Link for SUSE-SU-2015:1757-1
- E-Mail link for SUSE-SU-2015:1757-1
- SUSE Security Ratings
- SUSE Bug 949660
- SUSE CVE CVE-2014-8178 page
- SUSE CVE CVE-2014-8179 page
Описание
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.
Затронутые продукты
Ссылки
- CVE-2014-8178
- SUSE Bug 949660
Описание
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.
Затронутые продукты
Ссылки
- CVE-2014-8179
- SUSE Bug 949660