CVE Vulnerabilities

CVE-2014-3499

Published: Jul 11, 2014 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
7.2 IMPORTANT
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
HIGH

Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Docker Docker 1.0.0 (including) 1.0.0 (including)
Fedora Fedoraproject 19 (including) 19 (including)
Fedora Fedoraproject 20 (including) 20 (including)
Red Hat Enterprise Linux 7 Extras RedHat docker-0:0.11.1-22.el7 *
Docker.io Ubuntu upstream *
Docker.io Ubuntu utopic *
Docker.io Ubuntu vivid *
Docker.io Ubuntu wily *
Docker.io Ubuntu yakkety *

References