SB2019121721 - Multiple vulnerabilities in Docker Docker



SB2019121721 - Multiple vulnerabilities in Docker Docker

Published: December 17, 2019 Updated: July 17, 2020

Security Bulletin ID SB2019121721
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2014-8179)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.


2) Input validation error (CVE-ID: CVE-2014-8178)

The vulnerability allows a local non-authenticated attacker to manipulate data.

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.


Remediation

Install update from vendor's website.