Candidate: CVE-2014-8179 PublicDate: 2019-12-17 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8179 Description: Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation. Ubuntu-Description: Notes: tyhicks> Most likely to occur when interacting with maliciously crafted docker images tyhicks> Significant refactoring of the code between Trusty and Vivid Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_docker.io: upstream: https://github.com/NathanMcCauley/docker/commit/56d463690f833baf3ea5f1599715070f649e7aca (1.8.3) upstream_docker.io: released (1.8.3) precise_docker.io: DNE precise/esm_docker.io: DNE trusty_docker.io: not-affected (code not present) trusty/esm_docker.io: DNE (trusty was not-affected [code not present]) vivid_docker.io: ignored (reached end-of-life) vivid/stable-phone-overlay_docker.io: DNE vivid/ubuntu-core_docker.io: DNE wily_docker.io: ignored (reached end-of-life) xenial_docker.io: released (1.10.3-0ubuntu6) yakkety_docker.io: ignored (reached end-of-life) zesty_docker.io: released (1.12.6-0ubuntu4) devel_docker.io: not-affected (1.13.1-0ubuntu4)