#VU20969 Insecure dynamic library loading in Docker - CVE-2019-14271
Published: September 10, 2019 / Updated: March 16, 2023
Docker
Docker Inc.
Description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to the application loads NSS libraries in docker cp
in an insecure manner. A local attacker can pass a specially crafted library file to the application and execute arbitrary code on the system with elevated privileges.