CVE-2014-9357: Critical severity Docker docker vulnerability
Published Dec 16, 2014
·Updated
Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the chroot for archive extraction.
Affected Software
1 affected component
Docker docker=1.3.2
Event History
Dec 16, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9357?
CVE-2014-9357 is a critical vulnerability that allows remote attackers to execute arbitrary code with root privileges.
2
How do I fix CVE-2014-9357?
To fix CVE-2014-9357, upgrade Docker to a version later than 1.3.2.
3
What is affected by CVE-2014-9357?
CVE-2014-9357 specifically affects Docker version 1.3.2.
4
What type of attack is associated with CVE-2014-9357?
CVE-2014-9357 is associated with remote code execution attacks through crafted images or Dockerfile builds.
5
Is CVE-2014-9357 still a threat?
CVE-2014-9357 poses a threat if users continue to run the vulnerable Docker version 1.3.2 without upgrading.