Memory corruption in Docker Registry - CVE-2017-11468

 

Memory corruption in Docker Registry - CVE-2017-11468

Published: September 5, 2017


Vulnerability identifier: #VU8100
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-11468
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to insufficient restriction of amount of user-supplied content. A remote attacker can use manifest endpoint to trigger memory corruption and cause the application to crash.

Successful exploitation of the vulnerability results in denial of service.

Affected software

Docker Registry
IBM Cloud Transformation Advisor
Netcool Operations Insight
IBM MQ Operator
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
SUSE Linux
Ubuntu
Fedora
docker-registry (Ubuntu package)
docker-distribution
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
Robotic Process Automation for Cloud Pak
IBM Supplied MQ Advanced Queue Manager Container images

How to mitigate CVE-2017-11468

Update to version 2.6.2.

IBM Cloud Transformation Advisor - update to 3.10.2
docker-registry (Ubuntu package) - addressed in versions Ubuntu Pro, 2.7.1+ds2-7ubuntu0.3, 2.8.1+ds1-2ubuntu1.1
Netcool Operations Insight - update to 1.6.12
IBM MQ Operator - addressed in versions 2.0.20, 3.1.1
docker-distribution - addressed in versions 2.6.2-1.git48294d9.fc25, 2.6.2-1.git48294d9.fc26
IBM Cloud Pak for Watson AIOps - update to 4.7.0
DB2 on Cloud Pak for Data - update to 4.8.4
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.16-r2, 9.3.5.0-r2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.32, 23.0.2.4
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.15
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.15

External References

Related Security Bulletins