Upstream information

CVE-2014-9358 at MITRE

Description

Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having important severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 6.4
Vector AV:N/AC:L/Au:N/C:P/I:P/A:N
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None
SUSE Bugzilla entries: 909709, 909747

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Module for Containers 12
  • docker >= 1.6.2-31.2
Patchnames:
SUSE Linux Enterprise Module for Containers 12 GA docker
SUSE Linux Enterprise Module for Containers 15
  • docker >= 17.09.1_ce-4.25
  • docker-bash-completion >= 17.09.1_ce-4.25
Patchnames:
SUSE Linux Enterprise Module for Containers 15 GA docker
SUSE Linux Enterprise Server 12
  • docker >= 1.4.1-16.1
Patchnames:
SUSE-SLE-SERVER-12-2015-28
SUSE Linux Enterprise Server for SAP Applications 12
  • docker >= 1.4.1-16.1
Patchnames:
SUSE-SLE-SERVER-12-2015-28
SUSE OpenStack Cloud 6
  • docker >= 1.9.1-58.1
Patchnames:
SUSE OpenStack Cloud 6 GA docker
openSUSE Tumbleweed
  • docker >= 1.12.3-4.1
  • docker-bash-completion >= 1.12.3-4.1
  • docker-test >= 1.12.3-4.1
  • docker-zsh-completion >= 1.12.3-4.1
Patchnames:
openSUSE Tumbleweed GA docker