Lucene search

K
ibmIBM798D4E37387ED52B71189BFCE5A9045CDE68E0BCB86034800752C227B59E8B9B
HistorySep 26, 2018 - 5:55 p.m.

Security Bulletin: Vulnerabilities in docker affect PowerKVM

2018-09-2617:55:02
www.ibm.com
9

0.001 Low

EPSS

Percentile

50.4%

Summary

PowerKVM is affected by vulnerabilities in docker. IBM has now addressed these vulnerabilities.

Vulnerability Details

CVEID: CVE-2017-14992 DESCRIPTION: Docker-CE (Also known as Moby) is vulnerable to a denial of service, caused by the lack of content verification. By using a specially-crafted image layer payload, a remote attacker could exploit this vulnerability to cause the application to crash.
CVSS Base Score: 5.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/134421&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID: CVE-2016-9962 DESCRIPTION: Docker Engine could allow a local authenticated attacker to gain elevated privileges on the system, caused by an error in the RunC when running as root. By using “runc exec”, an attacker could exploit this vulnerability to gain access to file-descriptors and escape or modify runC state.
CVSS Base Score: 7.8
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/120498&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

PowerKVM V3.1

Remediation/Fixes

Customers can update PowerKVM systems by using “yum update”.

Fix images are made available via Fix Central. See <https://ibm.biz/BdHggw&gt;. This issue is addressed starting with v3.1.0.2 update 15.

Workarounds and Mitigations

none

CPENameOperatorVersion
powerkvmeq3.1