CVE-2018-15664
Summary
| CVE | CVE-2018-15664 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-23 14:29:00 UTC |
| Updated | 2019-06-25 12:15:00 UTC |
| Description | In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen filesystem (or from within a chroot). |
Risk And Classification
Problem Types: CWE-362
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Docker | Docker | 17.06.0-ce | All | All | All |
| Application | Docker | Docker | 17.06.0-ce | rc1 | All | All |
| Application | Docker | Docker | 17.06.0-ce | rc2 | All | All |
| Application | Docker | Docker | 17.06.0-ce | rc3 | All | All |
| Application | Docker | Docker | 17.06.0-ce | rc4 | All | All |
| Application | Docker | Docker | 17.06.0-ce | rc5 | All | All |
| Application | Docker | Docker | 17.06.1-ce | All | All | All |
| Application | Docker | Docker | 17.06.1-ce | rc1 | All | All |
| Application | Docker | Docker | 17.06.1-ce | rc2 | All | All |
| Application | Docker | Docker | 17.06.1-ce | rc3 | All | All |
| Application | Docker | Docker | 17.06.1-ce | rc4 | All | All |
| Application | Docker | Docker | 17.06.2-ce | All | All | All |
| Application | Docker | Docker | 17.06.2-ce | rc1 | All | All |
| Application | Docker | Docker | 17.07.0-ce | All | All | All |
| Application | Docker | Docker | 17.07.0-ce | rc1 | All | All |
| Application | Docker | Docker | 17.07.0-ce | rc2 | All | All |
| Application | Docker | Docker | 17.07.0-ce | rc3 | All | All |
| Application | Docker | Docker | 17.07.0-ce | rc4 | All | All |
| Application | Docker | Docker | 17.09.0-ce | All | All | All |
| Application | Docker | Docker | 17.09.0-ce | rc1 | All | All |
| Application | Docker | Docker | 17.09.0-ce | rc2 | All | All |
| Application | Docker | Docker | 17.09.0-ce | rc3 | All | All |
| Application | Docker | Docker | 17.09.1-ce | All | All | All |
| Application | Docker | Docker | 17.09.1-ce- | rc1 | All | All |
| Application | Docker | Docker | 17.10.0-ce | All | All | All |
| Application | Docker | Docker | 17.10.0-ce | rc1 | All | All |
| Application | Docker | Docker | 17.10.0-ce | rc2 | All | All |
| Application | Docker | Docker | 17.11.0-ce | All | All | All |
| Application | Docker | Docker | 17.11.0-ce | rc1 | All | All |
| Application | Docker | Docker | 17.11.0-ce | rc2 | All | All |
| Application | Docker | Docker | 17.11.0-ce | rc3 | All | All |
| Application | Docker | Docker | 17.11.0-ce | rc4 | All | All |
| Application | Docker | Docker | 17.12.0-ce | All | All | All |
| Application | Docker | Docker | 17.12.0-ce | rc1 | All | All |
| Application | Docker | Docker | 17.12.0-ce | rc2 | All | All |
| Application | Docker | Docker | 17.12.0-ce | rc3 | All | All |
| Application | Docker | Docker | 17.12.0-ce | rc4 | All | All |
| Application | Docker | Docker | 17.12.1-ce | All | All | All |
| Application | Docker | Docker | 17.12.1-ce | rc1 | All | All |
| Application | Docker | Docker | 17.12.1-ce | rc2 | All | All |
| Application | Docker | Docker | 18.01.0-ce | All | All | All |
| Application | Docker | Docker | 18.01.0-ce | rc1 | All | All |
| Application | Docker | Docker | 18.02.0-ce | All | All | All |
| Application | Docker | Docker | 18.02.0-ce | rc1 | All | All |
| Application | Docker | Docker | 18.02.0-ce | rc2 | All | All |
| Application | Docker | Docker | 18.03.0-ce | All | All | All |
| Application | Docker | Docker | 18.03.0-ce | rc1 | All | All |
| Application | Docker | Docker | 18.03.0-ce | rc2 | All | All |
| Application | Docker | Docker | 18.03.0-ce | rc3 | All | All |
| Application | Docker | Docker | 18.03.0-ce | rc4 | All | All |
| Application | Docker | Docker | 18.03.1-ce | All | All | All |
| Application | Docker | Docker | 18.03.1-ce | rc1 | All | All |
| Application | Docker | Docker | 18.03.1-ce | rc2 | All | All |
| Application | Docker | Docker | 18.04.0-ce | All | All | All |
| Application | Docker | Docker | 18.04.0-ce | rc1 | All | All |
| Application | Docker | Docker | 18.04.0-ce | rc2 | All | All |
| Application | Docker | Docker | 18.05.0-ce | All | All | All |
| Application | Docker | Docker | 18.05.0-ce | rc1 | All | All |
| Application | Docker | Docker | 18.06.0-ce | All | All | All |
| Application | Docker | Docker | 18.06.0-ce | rc1 | All | All |
| Application | Docker | Docker | 18.06.0-ce | rc2 | All | All |
| Application | Docker | Docker | 18.06.0-ce | rc3 | All | All |
| Application | Docker | Docker | 18.06.1-ce | rc1 | All | All |
| Application | Docker | Docker | 18.06.1-ce | rc2 | All | All |
| Application | Docker | Docker | 17.06.0-ce | All | All | All |
| Application | Docker | Docker | 17.06.0-ce | rc1 | All | All |
| Application | Docker | Docker | 17.06.0-ce | rc2 | All | All |
| Application | Docker | Docker | 17.06.0-ce | rc3 | All | All |
| Application | Docker | Docker | 17.06.0-ce | rc4 | All | All |
| Application | Docker | Docker | 17.06.0-ce | rc5 | All | All |
| Application | Docker | Docker | 17.06.1-ce | All | All | All |
| Application | Docker | Docker | 17.06.1-ce | rc1 | All | All |
| Application | Docker | Docker | 17.06.1-ce | rc2 | All | All |
| Application | Docker | Docker | 17.06.1-ce | rc3 | All | All |
| Application | Docker | Docker | 17.06.1-ce | rc4 | All | All |
| Application | Docker | Docker | 17.06.2-ce | All | All | All |
| Application | Docker | Docker | 17.06.2-ce | rc1 | All | All |
| Application | Docker | Docker | 17.07.0-ce | All | All | All |
| Application | Docker | Docker | 17.07.0-ce | rc1 | All | All |
| Application | Docker | Docker | 17.07.0-ce | rc2 | All | All |
| Application | Docker | Docker | 17.07.0-ce | rc3 | All | All |
| Application | Docker | Docker | 17.07.0-ce | rc4 | All | All |
| Application | Docker | Docker | 17.09.0-ce | All | All | All |
| Application | Docker | Docker | 17.09.0-ce | rc1 | All | All |
| Application | Docker | Docker | 17.09.0-ce | rc2 | All | All |
| Application | Docker | Docker | 17.09.0-ce | rc3 | All | All |
| Application | Docker | Docker | 17.09.1-ce | All | All | All |
| Application | Docker | Docker | 17.09.1-ce- | rc1 | All | All |
| Application | Docker | Docker | 17.10.0-ce | All | All | All |
| Application | Docker | Docker | 17.10.0-ce | rc1 | All | All |
| Application | Docker | Docker | 17.10.0-ce | rc2 | All | All |
| Application | Docker | Docker | 17.11.0-ce | All | All | All |
| Application | Docker | Docker | 17.11.0-ce | rc1 | All | All |
| Application | Docker | Docker | 17.11.0-ce | rc2 | All | All |
| Application | Docker | Docker | 17.11.0-ce | rc3 | All | All |
| Application | Docker | Docker | 17.11.0-ce | rc4 | All | All |
| Application | Docker | Docker | 17.12.0-ce | All | All | All |
| Application | Docker | Docker | 17.12.0-ce | rc1 | All | All |
| Application | Docker | Docker | 17.12.0-ce | rc2 | All | All |
| Application | Docker | Docker | 17.12.0-ce | rc3 | All | All |
| Application | Docker | Docker | 17.12.0-ce | rc4 | All | All |
| Application | Docker | Docker | 17.12.1-ce | All | All | All |
| Application | Docker | Docker | 17.12.1-ce | rc1 | All | All |
| Application | Docker | Docker | 17.12.1-ce | rc2 | All | All |
| Application | Docker | Docker | 18.01.0-ce | All | All | All |
| Application | Docker | Docker | 18.01.0-ce | rc1 | All | All |
| Application | Docker | Docker | 18.02.0-ce | All | All | All |
| Application | Docker | Docker | 18.02.0-ce | rc1 | All | All |
| Application | Docker | Docker | 18.02.0-ce | rc2 | All | All |
| Application | Docker | Docker | 18.03.0-ce | All | All | All |
| Application | Docker | Docker | 18.03.0-ce | rc1 | All | All |
| Application | Docker | Docker | 18.03.0-ce | rc2 | All | All |
| Application | Docker | Docker | 18.03.0-ce | rc3 | All | All |
| Application | Docker | Docker | 18.03.0-ce | rc4 | All | All |
| Application | Docker | Docker | 18.03.1-ce | All | All | All |
| Application | Docker | Docker | 18.03.1-ce | rc1 | All | All |
| Application | Docker | Docker | 18.03.1-ce | rc2 | All | All |
| Application | Docker | Docker | 18.04.0-ce | All | All | All |
| Application | Docker | Docker | 18.04.0-ce | rc1 | All | All |
| Application | Docker | Docker | 18.04.0-ce | rc2 | All | All |
| Application | Docker | Docker | 18.05.0-ce | All | All | All |
| Application | Docker | Docker | 18.05.0-ce | rc1 | All | All |
| Application | Docker | Docker | 18.06.0-ce | All | All | All |
| Application | Docker | Docker | 18.06.0-ce | rc1 | All | All |
| Application | Docker | Docker | 18.06.0-ce | rc2 | All | All |
| Application | Docker | Docker | 18.06.0-ce | rc3 | All | All |
| Application | Docker | Docker | 18.06.1-ce | rc1 | All | All |
| Application | Docker | Docker | 18.06.1-ce | rc2 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 1096726 – VUL-0: CVE-2018-15664: docker: 'docker cp' is vulnerable to symlink-exchange race attacks | MISC | bugzilla.suse.com | Exploit, Issue Tracking, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| oss-security - RE: CVE-2018-15664: docker (all versions) is vulnerable to a symlink-race attack | MLIST | www.openwall.com | |
| [security-announce] openSUSE-SU-2019:2044-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2019:1621-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| USN-4048-1: Docker vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| Docker CVE-2018-15664 Symlink Directory Traversal Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Footer Resource links | CONFIRM | portal.msrc.microsoft.com | |
| daemon: archive: pause containers before doing filesystem operations by cyphar · Pull Request #39252 · moby/moby · GitHub | MISC | github.com | Issue Tracking, Third Party Advisory |
| oss-security - CVE-2018-15664: docker (all versions) is vulnerable to a symlink-race attack | MLIST | www.openwall.com | Exploit, Mailing List, Third Party Advisory |
| CVE-2018-15664 - Red Hat Customer Portal | MISC | access.redhat.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.