Candidate: CVE-2016-3697 PublicDate: 2016-06-01 20:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3697 https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091 (runc, v0.1.0) https://github.com/docker/docker/commit/da38ac6c79fe902ed0687afc73d731c95c6d491a (docker) Description: libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container. Ubuntu-Description: Notes: leosilva> debian claims that the code is not present in docker.io. leosilva> in all the case runc is not affected anyway. Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_runc: upstream_runc: released (0.1.0+dfsg-1) precise_runc: DNE precise/esm_runc: DNE trusty_runc: DNE trusty/esm_runc: DNE vivid/stable-phone-overlay_runc: DNE vivid/ubuntu-core_runc: DNE wily_runc: DNE xenial_runc: not-affected (1.0.0~rc2+docker1.12.6-0ubuntu1~16.04.1) yakkety_runc: ignored (reached end-of-life) zesty_runc: released (1.0.0~rc2+docker1.12.6-0ubuntu1) devel_runc: released (1.0.0~rc2+docker1.13.1-0ubuntu1) Patches_docker.io: upstream_docker.io: needs-triage precise_docker.io: DNE precise/esm_docker.io: DNE trusty_docker.io: not-affected trusty/esm_docker.io: DNE (trusty was not-affected) vivid/stable-phone-overlay_docker.io: DNE vivid/ubuntu-core_docker.io: DNE wily_docker.io: ignored (reached end-of-life) xenial_docker.io: not-affected yakkety_docker.io: ignored (reached end-of-life) zesty_docker.io: not-affected devel_docker.io: not-affected