Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the chroot for archive extraction.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade docker.io | Jul 30, 2024 | Dec 16, 2014 |
| Docker | — | Upgrade to Docker v1.3.3 | May 4, 2017 | Dec 16, 2014 |
| Oracle_linux | — | Upgrade dockerUpgrade docker-pkg-develUpgrade docker-devel | Oct 16, 2024 | Dec 16, 2014 |
| Suse | — | Upgrade dockerUpgrade docker-bash-completionUpgrade docker-fish-completion | Dec 18, 2015 | Dec 16, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub