Memory corruption in Docker Registry - CVE-2017-11468
Published: September 5, 2017
Vulnerability identifier: #VU8100
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-11468
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to insufficient restriction of amount of user-supplied content. A remote attacker can use manifest endpoint to trigger memory corruption and cause the application to crash.
Successful exploitation of the vulnerability results in denial of service.
The weakness exists due to insufficient restriction of amount of user-supplied content. A remote attacker can use manifest endpoint to trigger memory corruption and cause the application to crash.
Successful exploitation of the vulnerability results in denial of service.
Affected software
Docker Registry
IBM Cloud Transformation Advisor
Netcool Operations Insight
IBM MQ Operator
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
SUSE Linux
Ubuntu
Fedora
docker-registry (Ubuntu package)
docker-distribution
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
Robotic Process Automation for Cloud Pak
IBM Supplied MQ Advanced Queue Manager Container images
IBM Cloud Transformation Advisor
Netcool Operations Insight
IBM MQ Operator
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
SUSE Linux
Ubuntu
Fedora
docker-registry (Ubuntu package)
docker-distribution
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
Robotic Process Automation for Cloud Pak
IBM Supplied MQ Advanced Queue Manager Container images
How to mitigate CVE-2017-11468
Update to version 2.6.2.
IBM Cloud Transformation Advisor - update to 3.10.2
docker-registry (Ubuntu package) - addressed in versions Ubuntu Pro, 2.7.1+ds2-7ubuntu0.3, 2.8.1+ds1-2ubuntu1.1
Netcool Operations Insight - update to 1.6.12
IBM MQ Operator - addressed in versions 2.0.20, 3.1.1
docker-distribution - addressed in versions 2.6.2-1.git48294d9.fc25, 2.6.2-1.git48294d9.fc26
IBM Cloud Pak for Watson AIOps - update to 4.7.0
DB2 on Cloud Pak for Data - update to 4.8.4
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.16-r2, 9.3.5.0-r2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.32, 23.0.2.4
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.15
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.15
docker-registry (Ubuntu package) - addressed in versions Ubuntu Pro, 2.7.1+ds2-7ubuntu0.3, 2.8.1+ds1-2ubuntu1.1
Netcool Operations Insight - update to 1.6.12
IBM MQ Operator - addressed in versions 2.0.20, 3.1.1
docker-distribution - addressed in versions 2.6.2-1.git48294d9.fc25, 2.6.2-1.git48294d9.fc26
IBM Cloud Pak for Watson AIOps - update to 4.7.0
DB2 on Cloud Pak for Data - update to 4.8.4
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.16-r2, 9.3.5.0-r2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.32, 23.0.2.4
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.15
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.15
External References
Related Security Bulletins
- Denial of service in Docker Registry
- OpenSUSE Linux update for docker-distribution
- Ubuntu update for docker-registry
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data
- Multiple vulnerabilities in IBM Robotic Process Automation
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Fedora 26 update for docker-distribution
- Fedora 25 update for docker-distribution