Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12043
HistoryJan 15, 2019 - 9:11 a.m.

Privilege Escalation

2019-01-1509:11:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.0004 Low

EPSS

Percentile

5.1%

github.com/opencontainers/runc is vulnerable to privilege escalation attacks. These attacks are possible because github.com/opencontainers/runc treats a numeric UID as a potential username. This allows local users to gain privileges though a numeric username in the password file. This transitively affects Docker.

References