UNIX symbolic link following in Docker - CVE-2015-3627
Published: August 30, 2022
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a symlink following issue, because Docker opens the file-descriptor passed to the pid-1 process before performing the chroot. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
Successful exploitation of this vulnerability may result in privilege escalation.
Affected software
QRadar Suite
DB2 Data Management Console
DataStage on Cloud Pak for Data
DB2 Data Management Console on CPD
Robotic Process Automation for Cloud Pak
IBM Robotic Process Automation
Netcool Operations Insight
IBM Decision Optimization for Cloud Pak for Data
IBM Match 360
Cloud Pak for Data
How to mitigate CVE-2015-3627
QRadar Suite - update to 1.10.21.0
DB2 Data Management Console - update to 3.1.13.1
IBM Robotic Process Automation - update to 21.0.3.1
Netcool Operations Insight - update to 1.6.9
IBM Decision Optimization for Cloud Pak for Data - update to 4.6.1
IBM Match 360 - update to 4.7.0
DataStage on Cloud Pak for Data - update to 4.7.3
DB2 Data Management Console on CPD - update to 4.8
Cloud Pak for Data - update to 4.8.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.7, 23.0.7
External References
- http://lists.opensuse.org/opensuse-updates/2015-05/msg00023.html
- http://packetstormsecurity.com/files/131835/Docker-Privilege-Escalation-Information-Disclosure.html
- http://seclists.org/fulldisclosure/2015/May/28
- https://groups.google.com/forum/#!searchin/docker-user/1.6.1/docker-user/47GZrihtr-4/nwgeOOFLexIJ
Related Security Bulletins
- Insecure link following in Docker
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- UNIX symbolic link following in IBM Decision Optimization in IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in ICP Match 360
- Multiple vulnerabilities in IBM QRadar Suite software
- IBM DataStage on Cloud Pak for Data update for Libcontainer and Docker Engine
- IBM Cloud Pak for Data update for Libcontainer and Docker Engine
- IBM DB2 Data Management Console update for Libcontainer and Docker Engine