Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.
CVSS Details
- CVSS 3.1 Base Score: 7.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade docker.io | Jul 30, 2024 | May 18, 2015 |
| Docker | — | Upgrade to Docker v1.6.1 | May 4, 2017 | May 18, 2015 |
| Oracle_linux | — | Upgrade docker-logrotateUpgrade dockerUpgrade docker-pkg-develUpgrade docker-zsh-completionUpgrade docker-vimUpgrade docker-devel | Oct 16, 2024 | May 18, 2015 |
| Suse | — | Upgrade docker-fish-completionUpgrade docker-bash-completionUpgrade docker | Dec 18, 2015 | May 18, 2015 |
| Ubuntu | — | Upgrade docker.io | Nov 19, 2024 | May 18, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub