imPC@ndo EN

Tracker / CVE-2019-5736

CVE-2019-5736

Alta 8.6

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

Prodotti e versioni affette

apache mesos · 1.4.0 → 1.4.3
apache mesos · 1.5.0 → 1.5.3
apache mesos · 1.6.0 → 1.6.2
apache mesos · 1.7.0 → 1.7.2
canonical ubuntu_linux
d2iq dc\/os · … → 1.10.10
d2iq dc\/os · 1.10.11 → 1.11.9
d2iq dc\/os · 1.11.10 → 1.12.1
d2iq kubernetes_engine · … → 2.2.0-1.13.3
docker docker · … → 18.09.2
fedoraproject fedora
google kubernetes_engine
hp onesphere
linuxcontainers lxc · … → 3.2.0
linuxfoundation runc
linuxfoundation runc · … → 0.1.1
microfocus service_management_automation
netapp hci_management_node
netapp solidfire
opensuse backports_sle
opensuse leap
redhat container_development_kit
redhat enterprise_linux
redhat enterprise_linux_server
redhat openshift

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti