5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
5.3 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
0.001 Low
EPSS
Percentile
49.5%
util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls
os.OpenFile with a potentially unsafe qemu-check temporary pathname,
constructed with an empty first argument in an ioutil.TempDir call.
Author | Note |
---|---|
mdeslaur | the patch looks like a windows-specific issue, the description is “Avoid creation of irrelevant temporary files on Windows.” and it basically only modified Windows code. Marking as not-affected. |
web.archive.org/web/20200530054359/docs.docker.com/engine/release-notes/
github.com/moby/buildkit/pull/1462
github.com/moby/moby/pull/40877
golang.org/pkg/io/ioutil/#TempDir
golang.org/pkg/os/#TempDir
launchpad.net/bugs/cve/CVE-2020-27534
nvd.nist.gov/vuln/detail/CVE-2020-27534
security-tracker.debian.org/tracker/CVE-2020-27534
www.cve.org/CVERecord?id=CVE-2020-27534
5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
5.3 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
0.001 Low
EPSS
Percentile
49.5%