Lucene search

K
cve[email protected]CVE-2014-9357
HistoryDec 16, 2014 - 6:59 p.m.

CVE-2014-9357

2014-12-1618:59:15
CWE-264
web.nvd.nist.gov
45
docker
1.3.2
remote code execution
lzma
archive
cve-2014-9357

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8.6 High

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.6%

Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the chroot for archive extraction.

Affected configurations

NVD
Node
dockerdockerMatch1.3.2
CPENameOperatorVersion
docker:dockerdockereq1.3.2

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8.6 High

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.6%