QID 353067
Date Published: 2021-12-14
QID 353067: Amazon Linux Security Advisory for docker : ALAS2DOCKER-2021-004
A flaw was discovered in the api endpoint behind the 'docker cp' command.
The endpoint is vulnerable to a time of check to time of use (toctou) vulnerability in the way it handles symbolic links inside a container.
An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container. (
( CVE-2018-15664)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
Solution
Please refer to Amazon advisory: ALAS2DOCKER-2021-004 for affected packages and patching details, or update with your package manager.
Vendor References
- ALAS2DOCKER-2021-004 -
alas.aws.amazon.com/AL2/ALASDOCKER-2021-004.html
CVEs related to QID 353067
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2DOCKER-2021-004 | Amazon Linux 2 |
|