CVE-2015-3627
Summary
| CVE | CVE-2015-3627 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-05-18 15:59:00 UTC |
| Updated | 2023-11-07 02:25:00 UTC |
| Description | Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 900005 CBL-Mariner Linux Security Update for moby-buildx 0.4.1
- 903078 Common Base Linux Mariner (CBL-Mariner) Security Update for moby-buildx (4416)