Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2016:3084-1

Опубликовано: 12 дек. 2016
Источник: suse-cvrf

Описание

Security update for Docker and dependencies

This update for Docker and its dependencies fixes the following issues:

  • fix runc and containerd revisions (bsc#1009961)

docker:

  • Updates version 1.11.2 to 1.12.3 (bsc#1004490, bsc#996015, bsc#995058)
  • Fix ambient capability usage in containers (bsc#1007249, CVE-2016-8867)
  • Change the internal mountpoint name to not use ':' as that character can be considered a special character by other tools. (bsc#999582)
  • Add dockerd(8) man page.
  • Package docker-proxy (which was split out of the docker binary in 1.12). (bsc#995620)
  • Docker 'migrator' prevents installing 'docker', if docker 1.9 was installed before but there were no images. (bsc#995102)
  • Specify an 'OCI' runtime for our runc package explicitly. (bsc#978260)
  • Use gcc6-go instead of gcc5-go (bsc#988408)

For a detailed description of all fixes and improvements, please refer to:

https://github.com/docker/docker/releases/tag/v1.12.3 https://github.com/docker/docker/blob/v1.12.2/CHANGELOG.md https://github.com/docker/docker/releases/tag/v1.12.1 https://github.com/docker/docker/releases/tag/v1.12.0

containerd:

  • Update to current version required from Docker 1.12.3.
  • Add missing Requires(post): %fillup_prereq. (bsc#1006368)
  • Use gcc6-go instead of gcc5-go. (bsc#988408)

runc:

  • Update to current version required from Docker 1.12.3.
  • Use gcc6-go instead of gcc5-go. (bsc#988408)

rubygem-excon:

  • Updates version from 0.39.6 to 0.52.0.

For a detailed description of all fixes and improvements, please refer to the installed changelog.txt.

rubygem-docker-api:

  • Updated version from 1.17.0 to 1.31.0.

Список пакетов

SUSE Linux Enterprise Module for Containers 12
containerd-0.2.4+gitr565_0366d7e-9.1
docker-1.12.3-81.2
ruby2.1-rubygem-docker-api-1.31.0-11.2
ruby2.1-rubygem-excon-0.52.0-9.1
runc-0.1.1+gitr2816_02f8fa7-9.1
SUSE OpenStack Cloud 6
containerd-0.2.4+gitr565_0366d7e-9.1
docker-1.12.3-81.2
runc-0.1.1+gitr2816_02f8fa7-9.1

Описание

Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.


Затронутые продукты
SUSE Linux Enterprise Module for Containers 12:containerd-0.2.4+gitr565_0366d7e-9.1
SUSE Linux Enterprise Module for Containers 12:docker-1.12.3-81.2
SUSE Linux Enterprise Module for Containers 12:ruby2.1-rubygem-docker-api-1.31.0-11.2
SUSE Linux Enterprise Module for Containers 12:ruby2.1-rubygem-excon-0.52.0-9.1

Ссылки