Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-9357
HistoryDec 16, 2014 - 12:00 a.m.

CVE-2014-9357

2014-12-1600:00:00
ubuntu.com
ubuntu.com
10

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.014 Low

EPSS

Percentile

86.6%

Docker 1.3.2 allows remote attackers to execute arbitrary code with root
privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA
(.xz) archive, related to the chroot for archive extraction.

Bugs

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.014 Low

EPSS

Percentile

86.6%