Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:1757-1

Опубликовано: 14 окт. 2015
Источник: suse-cvrf

Описание

Security update for docker

docker was updated to version 1.8.3 to fix two security issues.

These security issues were fixed:

  • CVE-2014-8178: Manipulated layer IDs could have lead to local graph poisoning (bsc#949660).
  • CVE-2014-8179: Manifest validation and parsing logic errors allowed pull-by-digest validation bypass (bsc#949660).

This non-security issues was fixed:

  • Add --disable-legacy-registry to prevent a daemon from using a v1 registry

More information about docker 1.8.3 can be found at https://blog.docker.com/2015/10/security-release-docker-1-8-3-1-6-2-cs7/

Список пакетов

SUSE Linux Enterprise Module for Containers 12
docker-1.8.3-49.1

Описание

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.


Затронутые продукты
SUSE Linux Enterprise Module for Containers 12:docker-1.8.3-49.1

Ссылки

Описание

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.


Затронутые продукты
SUSE Linux Enterprise Module for Containers 12:docker-1.8.3-49.1

Ссылки