Docker · Docker Engine · CVE-2015-3630
**Name of the Vulnerable Software and Affected Versions**
Docker Engine versions prior to 1.6.1
**Description**
The issue allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image. This is due to weak permissions for certain /proc files, including `/proc/asound`, `/proc/timer stats`, `/proc/latency stats`, and `/proc/fs`.
**Recommendations**
For Docker Engine versions prior to 1.6.1, update to version 1.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable /proc files to minimize the risk of exploitation.