Lucene search

K
redhatRedHatRHSA-2017:2603
HistorySep 05, 2017 - 10:16 a.m.

(RHSA-2017:2603) Low: docker-distribution security, bug fix, and enhancement update

2017-09-0510:16:55
access.redhat.com
62

0.005 Low

EPSS

Percentile

75.9%

The docker-distribution package provides the tool set to support the Docker Registry version 2.

The following packages have been upgraded to a later upstream version: docker-distribution (2.6.2). (BZ#1479494)

Security Fix(es):

  • It was found that docker-distribution did not properly restrict memory allocation size for a registry instance through the manifest endpoint. An attacker could send a specially crafted request that would exhaust the memory of the docker-distribution service. (CVE-2017-11468)