First published: Fri Jun 20 2014(Updated: )
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Docker | =1.0.0 | |
Fedora | =19 | |
Fedora | =20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-3499 is classified as high due to its potential to allow local users to gain elevated privileges.
To fix CVE-2014-3499, restrict the permissions on the Docker management socket to prevent world-readable and world-writable access.
CVE-2014-3499 specifically affects Docker version 1.0.0.
Yes, Fedora versions 19 and 20 are also affected by CVE-2014-3499.
CVE-2014-3499 is a permissions vulnerability that allows local users to exploit Docker's management socket.