Lucene search

K
ibmIBM839351F31000EA738AD6302B138957D7FEE614C0FBF4C18587C9731E7ED79FF1
HistoryFeb 18, 2019 - 8:15 p.m.

Security Bulletin: IBM Cloud Functions is affected by a privilege escalation vulnerability in runc

2019-02-1820:15:01
www.ibm.com
14

0.004 Low

EPSS

Percentile

73.6%

Summary

IBM Cloud Functions is affected by a security vulnerability in runc which could allow an attacker, authorized to run a process as root inside a container, to execute arbitrary commands with root privileges on the container’s host system.

Vulnerability Details

CVEID: CVE-2019-5736

DESCRIPTION: Runc could allow a local attacker to execute arbitrary commands on the system, cause by the improper handling of system file descriptors when running containers. An attacker could exploit this vulnerability using a malicious container to overwrite the contents of the host runc binary and execute arbitrary commands with root privileges on the host system.

CVSS Base Score: 7.7
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/156819&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)

Affected Products and Versions

All versions of IBM Cloud Functions are impacted.

Remediation/Fixes

IBM Cloud Functions has been updated with a fix that addresses this vulnerability. This bulletin is for informational purposes only. There is no further action required for IBM Cloud Functions users.

CPENameOperatorVersion
ibm cloud functionseqany