Bugzilla – Bug 909710
VUL-0: CVE-2014-9357: docker: Escalation of privileges during decompression of LZMA archives
Last modified: 2018-12-14 15:10:22 UTC
rh#1172782 Docker Inc. has discovered an issue whereby a malicious image could execute arbitrary code when being unpacked automatically after a "docker pull". From the Docker Inc report: "It has been discovered that the introduction of chroot for archive extraction in Docker 1.3.2 had introduced a privilege escalation vulnerability. Malicious images or builds from malicious Dockerfiles could escalate privileges and execute arbitrary code as a root user on the Docker host by providing a malicious ‘xz’ binary. We are releasing Docker 1.3.3 to address this vulnerability. Only Docker 1.3.2 is vulnerable. Users are highly encouraged to upgrade." CVE-2014-9357 was assigned to this issue. References: https://groups.google.com/forum/#!topic/docker-user/nFAz-B-n4Bw https://bugzilla.redhat.com/show_bug.cgi?id=1172782 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9357 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9357
This is an autogenerated message for OBS integration: This bug (909710) was mentioned in https://build.opensuse.org/request/show/265019 13.2 / docker
If possible I would release the original docker update first and then start the next update right afterwards on SLE12.
Yeah, this is possible.
acfcepted to sle12 and 13.2. do not forget factory too!
Fixed.
This is an autogenerated message for OBS integration: This bug (909710) was mentioned in https://build.opensuse.org/request/show/265920 Factory / docker
openSUSE-SU-2014:1722-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 909709,909710,909712 CVE References: CVE-2014-9356,CVE-2014-9357,CVE-2014-9358 Sources used: openSUSE 13.2 (src): docker-1.4.0-13.1
SUSE-SU-2015:0082-1: An update that solves three vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 909709,909710,909712,913211,913213 CVE References: CVE-2014-9356,CVE-2014-9357,CVE-2014-9358 Sources used: SUSE Linux Enterprise Server 12 (src): docker-1.4.1-16.1