Bug 907012 (CVE-2014-6407) - VUL-0: CVE-2014-6407: docker: symbolic and hardlink issues leading to privilege escalation
Summary: VUL-0: CVE-2014-6407: docker: symbolic and hardlink issues leading to privile...
Status: RESOLVED FIXED
Alias: CVE-2014-6407
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/110993/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-11-25 09:08 UTC by Johannes Segitz
Modified: 2018-12-14 15:10 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-11-25 09:08:06 UTC
The Docker engine, up to and including version 1.3.1, was vulnerable to
extracting files to arbitrary paths on the host during ‘docker pull’ and
‘docker load’ operations. This was caused by symlink and hardlink
traversals present in Docker's image extraction. This vulnerability could
be leveraged to perform remote code execution and privilege escalation.

Docker 1.3.2 remedies this vulnerability. Additional checks have been added
to pkg/archive and image extraction is now performed in a chroot. No
remediation is available for older versions of Docker and users are advised
to upgrade.

Affects SLE 12 and openSUSE 13.2. Requires using an untrusted external repo, which is a bad idea anyway.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1167505
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6407
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6407
http://seclists.org/oss-sec/2014/q4/781
Comment 1 Swamp Workflow Management 2014-11-25 23:00:24 UTC
bugbot adjusting priority
Comment 2 Flavio Castelli 2014-11-27 13:43:25 UTC
Maintenance request submitted.
Comment 3 Marcus Meissner 2014-11-27 20:47:06 UTC
accepted and merged
Comment 4 Swamp Workflow Management 2014-12-08 16:08:00 UTC
openSUSE-SU-2014:1596-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 907012,907014
CVE References: CVE-2014-6407,CVE-2014-6408
Sources used:
openSUSE 13.2 (src):    docker-1.3.2-9.1
Comment 5 Swamp Workflow Management 2014-12-15 13:05:21 UTC
SUSE-SU-2014:1648-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 898901,902289,902413,907012,907014
CVE References: CVE-2014-5277,CVE-2014-5282,CVE-2014-6407,CVE-2014-6408,CVE-2014-7189
Sources used:
SUSE Linux Enterprise Server 12 (src):    docker-1.3.2-9.1, sle2docker-0.2.3-5.1
Comment 6 Marcus Meissner 2014-12-15 13:17:59 UTC
done