PT-2014-8957 · Docker+1 · Docker+1
CVE-2014-9357
·
Publicado
2014-12-16
·
Atualizado
2025-10-11
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Docker version 1.3.2
Description
The issue allows remote attackers to execute arbitrary code with root privileges. This can be achieved via a crafted image or build in a Dockerfile, specifically when the image or build is contained in an LZMA (.xz) archive. The problem is related to the chroot used for archive extraction.
Recommendations
For Docker version 1.3.2, consider restricting the use of LZMA (.xz) archives until a patch is available. As a temporary workaround, avoid using crafted images or builds in Dockerfiles that could exploit this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Improper Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Docker
Suse