UNIX symbolic link following in Docker - CVE-2015-3627

 

UNIX symbolic link following in Docker - CVE-2015-3627

Published: August 30, 2022


Vulnerability identifier: #VU66857
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3627
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a symlink following issue, because Docker opens the file-descriptor passed to the pid-1 process before performing the chroot. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.

Successful exploitation of this vulnerability may result in privilege escalation.


Affected software

Docker
QRadar Suite
DB2 Data Management Console
DataStage on Cloud Pak for Data
DB2 Data Management Console on CPD
Robotic Process Automation for Cloud Pak
IBM Robotic Process Automation
Netcool Operations Insight
IBM Decision Optimization for Cloud Pak for Data
IBM Match 360
Cloud Pak for Data

How to mitigate CVE-2015-3627

Install updates from vendor's website.

Docker - update to 1.6.1
QRadar Suite - update to 1.10.21.0
DB2 Data Management Console - update to 3.1.13.1
IBM Robotic Process Automation - update to 21.0.3.1
Netcool Operations Insight - update to 1.6.9
IBM Decision Optimization for Cloud Pak for Data - update to 4.6.1
IBM Match 360 - update to 4.7.0
DataStage on Cloud Pak for Data - update to 4.7.3
DB2 Data Management Console on CPD - update to 4.8
Cloud Pak for Data - update to 4.8.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.7, 23.0.7

External References

Related Security Bulletins