CVE-2015-3630
Published: 18 May 2015
Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.
Priority
Status
Package | Release | Status |
---|---|---|
docker.io Launchpad, Ubuntu, Debian |
precise |
Does not exist
|
trusty |
Released
(1.6.2~dfsg1-1ubuntu4~14.04.1)
|
|
upstream |
Released
(1.6.1)
|
|
utopic |
Ignored
(end of life)
|
|
vivid |
Ignored
(end of life)
|
|
wily |
Ignored
(end of life)
|
|
xenial |
Released
(1.6.2~dfsg1-1ubuntu4)
|
|
yakkety |
Ignored
(end of life)
|
|
zesty |
Not vulnerable
(1.10.3-0ubuntu6)
|