CVE Vulnerabilities

CVE-2014-9357

Published: Dec 16, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
4.6 LOW
AV:A/AC:H/Au:N/C:N/I:C/A:N
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the chroot for archive extraction.

Affected Software

NameVendorStart VersionEnd Version
DockerDocker1.3.2 (including)1.3.2 (including)
Red Hat Enterprise Linux 7 ExtrasRedHatdocker-0:1.4.1-37.el7*
Docker.ioUbuntuupstream*

References