PT-2015-6250 · Docker+2 · Docker Engine+3

Eric Windisch

·

Publicado

2015-05-08

·

Atualizado

2025-10-11

·

CVE-2015-3630

CVSS v3.1

8.4

Alta

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Docker Engine versions prior to 1.6.1
Description The issue allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image. This is due to weak permissions for certain /proc files, including /proc/asound, /proc/timer stats, /proc/latency stats, and /proc/fs.
Recommendations For Docker Engine versions prior to 1.6.1, update to version 1.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable /proc files to minimize the risk of exploitation.

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1429
CVE-2015-3630
GHSA-8FVR-5RQF-3WWH
GO-2022-0638
OPENSUSE-SU-2024:10532-1
OPENSUSE-SU-2025:15589-1
SUSE-SU-2015:0984-1
SUSE-SU-2025:03540-1
SUSE-SU-2025:03545-1

Produtos afetados

Alt Linux
Docker
Docker Engine
Suse