漏洞标题
N/A
漏洞描述信息
Docker软件包版本docker-1.13.1-108.git4ef4b30.el7通过 RHBA-2020:0053(https://access.redhat.com/errata/RHBA-2020:0053)发布到Red Hat Enterprise Linux 7 Extras中,并通过 RHBA-2017:0116(https://access.redhat.com/errata/RHSA-2017:0116)进行修正。CVE-2020-14300 assigned 给这个安全 regression,而该 regression 特定于由 Red Hat 生产的 Docker 软件包。原始问题 - CVE-2016-9962 - 可能导致容器内的进程危及进入容器命名空间的进程,并在容器外执行任意代码。这可能导致容器主机或同一容器主机上运行的其他容器被危及。该问题只影响 Red Hat Enterprise Linux 7 中 shipping 的 Docker 1.13.1-108.git4ef4b30 版本。早期的和晚期的版本均不受影响。
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that update was the fix for CVE-2016-9962, that was previously corrected in the docker packages in Red Hat Enterprise Linux 7 Extras via RHSA-2017:0116 (https://access.redhat.com/errata/RHSA-2017:0116). The CVE-2020-14300 was assigned to this security regression and it is specific to the docker packages produced by Red Hat. The original issue - CVE-2016-9962 - could possibly allow a process inside container to compromise a process entering container namespace and execute arbitrary code outside of the container. This could lead to compromise of the container host or other containers running on the same container host. This issue only affects a single version of Docker, 1.13.1-108.git4ef4b30, shipped in Red Hat Enterprise Linux 7. Both earlier and later versions are not affected.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
Docker 安全漏洞
漏洞描述信息
Docker是美国Docker公司的一款开源的应用容器引擎。该产品支持在Linux系统上创建一个容器(轻量级虚拟机)并部署和运行应用程序,以及通过配置文件实现应用程序的自动化安装、部署和升级。 Docker 1.13.1-108.git4ef4b30.el7版本(使用在Red Hat Enterprise Linux 7版本)中的runc存在安全漏洞。攻击者可利用该漏洞入侵容器主机或该主机上其他容器。
CVSS信息
N/A
漏洞类别
其他