Double Free in docker-credential-helpers - CVE-2019-1020014
Published: August 5, 2019 / Updated: August 5, 2019
Vulnerability identifier: #VU19934
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1020014
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to access sensitive information on a targeted system.
The vulnerability exists due to a double free condition in the list functions. A local authenticated attacker can trigger double free error and gain access to sensitive information on a targeted system
Affected software
docker-credential-helpers
golang-github-docker-docker-credential-helpers (Ubuntu package)
docker.io (Ubuntu package)
golang-github-docker-credential-helpers
Opensuse
Fedora
golang-github-docker-docker-credential-helpers (Ubuntu package)
docker.io (Ubuntu package)
golang-github-docker-credential-helpers
Opensuse
Fedora
How to mitigate CVE-2019-1020014
Install updates from vendor's website.
docker-credential-helpers - update to 0.6.3
golang-github-docker-docker-credential-helpers (Ubuntu package) - update to 0.6.1-1ubuntu0.1
docker.io (Ubuntu package) - addressed in versions 18.09.7-0ubuntu1~16.04.5, 18.09.7-0ubuntu1~18.04.4, 18.09.7-0ubuntu1~19.04.5
golang-github-docker-credential-helpers - update to 0.6.3-2.fc32
golang-github-docker-docker-credential-helpers (Ubuntu package) - update to 0.6.1-1ubuntu0.1
docker.io (Ubuntu package) - addressed in versions 18.09.7-0ubuntu1~16.04.5, 18.09.7-0ubuntu1~18.04.4, 18.09.7-0ubuntu1~19.04.5
golang-github-docker-credential-helpers - update to 0.6.3-2.fc32