Candidate: CVE-2014-8178 PublicDate: 2019-12-17 14:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8178 Description: Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands. Ubuntu-Description: Notes: tyhicks> Most likely to occur when interacting with maliciously crafted docker images tyhicks> Significant refactoring of the code between Trusty and Vivid Bugs: Priority: low Discovered-by: Florian Weimer and Tõnis Tiigi Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N [5.5 MEDIUM] Patches_docker.io: upstream: https://github.com/aaronlehmann/docker/commit/504e67b867865a2835e8002c01087a2cfd7bfd0e (master) upstream: https://github.com/NathanMcCauley/docker/commit/9098628b2901ae8585ba4c66ee6e14759d2119da (1.8.3) upstream_docker.io: released (1.8.3) precise_docker.io: DNE precise/esm_docker.io: DNE trusty_docker.io: ignored (reached end-of-life) trusty/esm_docker.io: DNE (trusty was deferred) vivid_docker.io: ignored (reached end-of-life) vivid/stable-phone-overlay_docker.io: DNE vivid/ubuntu-core_docker.io: DNE wily_docker.io: ignored (reached end-of-life) xenial_docker.io: released (1.10.3-0ubuntu6) yakkety_docker.io: ignored (reached end-of-life) zesty_docker.io: released (1.12.6-0ubuntu4) artful_docker.io: not-affected (1.13.1-0ubuntu4) bionic_docker.io: not-affected (1.13.1-0ubuntu4) cosmic_docker.io: not-affected (1.13.1-0ubuntu4) disco_docker.io: not-affected (1.13.1-0ubuntu4) devel_docker.io: not-affected (1.13.1-0ubuntu4)