Bug 909709 (CVE-2014-9358) - VUL-0: CVE-2014-9358: docker: Path traversal and spoofing opportunities presented through image identifiers
Summary: VUL-0: CVE-2014-9358: docker: Path traversal and spoofing opportunities prese...
Status: RESOLVED FIXED
Alias: CVE-2014-9358
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/111523/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-12-12 13:45 UTC by Alexander Bergmann
Modified: 2018-12-14 15:10 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2014-12-12 13:45:45 UTC
rh#1172787

Docker Inc. has reported that it is possible to spoof images on the central registry. From the report: 

"It has been discovered that Docker does not sufficiently validate Image IDs as provided either via 'docker load' or through registry communications. This allows for path traversal attacks, causing graph corruption and manipulation by malicious images, as well as repository spoofing attacks."




References:
https://groups.google.com/forum/#!topic/docker-user/nFAz-B-n4Bw
https://bugzilla.redhat.com/show_bug.cgi?id=1172787
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9358
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9358
Comment 1 Alexander Bergmann 2014-12-12 13:47:52 UTC
CVE-2014-9358 was assigned to this issue.
Comment 3 Bernhard Wiedemann 2014-12-12 17:00:21 UTC
This is an autogenerated message for OBS integration:
This bug (909709) was mentioned in
https://build.opensuse.org/request/show/265019 13.2 / docker
Comment 6 Marcus Meissner 2014-12-18 17:57:58 UTC
accepted to sle12 and 13.2. do not forget factory
Comment 7 Flavio Castelli 2014-12-19 12:55:22 UTC
Thanks. The package is already inside of the Virtualization project, which is automatically pulled by Factory for updates. However, given all the security implications, I'll file a SR.

In the meantime, closing as resolved.
Comment 8 Bernhard Wiedemann 2014-12-19 13:01:07 UTC
This is an autogenerated message for OBS integration:
This bug (909709) was mentioned in
https://build.opensuse.org/request/show/265920 Factory / docker
Comment 9 Swamp Workflow Management 2014-12-27 21:07:35 UTC
openSUSE-SU-2014:1722-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 909709,909710,909712
CVE References: CVE-2014-9356,CVE-2014-9357,CVE-2014-9358
Sources used:
openSUSE 13.2 (src):    docker-1.4.0-13.1
Comment 10 Swamp Workflow Management 2015-01-19 16:04:51 UTC
SUSE-SU-2015:0082-1: An update that solves three vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 909709,909710,909712,913211,913213
CVE References: CVE-2014-9356,CVE-2014-9357,CVE-2014-9358
Sources used:
SUSE Linux Enterprise Server 12 (src):    docker-1.4.1-16.1