[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2019-1245

ID: oval:org.secpod.oval:def:1601024Date: (C)2019-07-30   (M)2021-09-12
Class: PATCHFamily: unix




A flaw was discovered in the API endpoint behind the 'docker cp' command. The endpoint is vulnerable to a Time Of Check to Time Of Use vulnerability in the way it handles symbolic links inside a container. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container

Platform:
Amazon Linux AMI
Product:
docker
Reference:
ALAS-2019-1245
CVE-2018-15664
CVE    1
CVE-2018-15664
CPE    2
cpe:/o:amazon:linux
cpe:/a:docker:docker

© SecPod Technologies