Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-6407

Опубликовано: 12 дек. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5

Описание

Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.

РелизСтатусПримечание
devel

not-affected

1.3.2~dfsg1-1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [1.6.2~dfsg1-1ubuntu4~14.04.1]]
esm-infra/xenial

not-affected

1.3.2~dfsg1-1
lucid

DNE

precise

DNE

precise/esm

DNE

trusty

not-affected

1.6.2~dfsg1-1ubuntu4~14.04.1
trusty/esm

DNE

trusty was not-affected [1.6.2~dfsg1-1ubuntu4~14.04.1]
upstream

released

1.3.2~dfsg1-1
utopic

ignored

end of life

Показывать по

Ссылки на источники

7.5 High

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.

nvd
около 11 лет назад

Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.

msrc
больше 4 лет назад

Описание отсутствует

debian
около 11 лет назад

Docker before 1.3.2 allows remote attackers to write to arbitrary file ...

CVSS3: 7.3
github
почти 4 года назад

Arbitrary Code Execution in Docker

7.5 High

CVSS2