CVE Vulnerabilities

CVE-2014-3499

Published: Jul 11, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
7.2 IMPORTANT
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
DockerDocker1.0.0 (including)1.0.0 (including)
FedoraFedoraproject19 (including)19 (including)
FedoraFedoraproject20 (including)20 (including)
Red Hat Enterprise Linux 7 ExtrasRedHatdocker-0:0.11.1-22.el7*
Docker.ioUbuntuupstream*
Docker.ioUbuntuutopic*
Docker.ioUbuntuvivid*
Docker.ioUbuntuwily*
Docker.ioUbuntuyakkety*

References