PT-2014-8957 · Docker+1 · Docker+1
Published
2014-12-16
·
Updated
2025-10-11
·
CVE-2014-9357
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Docker version 1.3.2
Description
The issue allows remote attackers to execute arbitrary code with root privileges. This can be achieved via a crafted image or build in a Dockerfile, specifically when the image or build is contained in an LZMA (.xz) archive. The problem is related to the chroot used for archive extraction.
Recommendations
For Docker version 1.3.2, consider restricting the use of LZMA (.xz) archives until a patch is available. As a temporary workaround, avoid using crafted images or builds in Dockerfiles that could exploit this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Docker
Suse