Docker CVE-2018-15664 Symlink Directory Traversal Vulnerability
BID:108507
CVE-2018-15664 |Info
Docker CVE-2018-15664 Symlink Directory Traversal Vulnerability
| Bugtraq ID: | 108507 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-15664 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2019 12:00AM |
| Updated: | May 28 2019 12:00AM |
| Credit: | Aleksa Sarai |
| Vulnerable: |
Docker Docker 0 |
| Not Vulnerable: | |
Discussion
Docker CVE-2018-15664 Symlink Directory Traversal Vulnerability
Docker is prone to a directory-traversal vulnerability.
An attacker may exploit this issue to gain read/write access to the files outside of the restricted directory; this may aid in further attacks.
Docker is prone to a directory-traversal vulnerability.
An attacker may exploit this issue to gain read/write access to the files outside of the restricted directory; this may aid in further attacks.
Exploit / POC
Docker CVE-2018-15664 Symlink Directory Traversal Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Docker CVE-2018-15664 Symlink Directory Traversal Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Docker CVE-2018-15664 Symlink Directory Traversal Vulnerability
References:
References:
- Docker - Homepage (Docker)
- Bug 1096726 - (CVE-2018-15664) VUL-0: CVE-2018-15664: docker: 'docker cp' is vu ()
- Properly handle paths with symlink path components #6000 ()
- cp command follows symlinks into the host filesystem, not the container #5619 ()
- CVE-2018-15664: docker (all versions) is vulnerable to a symlink-race attack ()
- daemon: archive: pause containers before doing filesystem operations #39252 (Github)