[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2014-461 ---- docker

ID: oval:org.secpod.oval:def:1600165Date: (C)2016-01-19   (M)2023-11-10
Class: PATCHFamily: unix




Path traversal attacks are possible in the processing of absolute symlinks. In checking symlinks for traversals, only relative links were considered. This allowed path traversals to exist where they should have otherwise been prevented. This was exploitable via both archive extraction and through volume mounts. This vulnerability allowed malicious images or builds from malicious Dockerfiles to write files to the host system and escape containerization, leading to privilege escalation. It has been discovered that the introduction of chroot for archive extraction in Docker 1.3.2 had introduced a privilege escalation vulnerability. Malicious images or builds from malicious Dockerfiles could escalate privileges and execute arbitrary code as a root user on the Docker host by providing a malicious "xz" binary. It has been discovered that Docker does not sufficiently validate Image IDs as provided either via "docker load" or through registry communications. This allows for path traversal attacks, causing graph corruption and manipulation by malicious images, as well as repository spoofing attacks

Platform:
Amazon Linux AMI
Product:
docker
Reference:
ALAS-2014-461
CVE-2014-9357
CVE-2014-9356
CVE-2014-9358
CVE    3
CVE-2014-9357
CVE-2014-9356
CVE-2014-9358
CPE    3
cpe:/o:amazon:linux
cpe:/a:docker:docker
cpe:/a:docker:docker:1.3.2

© SecPod Technologies