CVE-2015-3630: High severity Docker docker vulnerability
Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timerstats, (3) /proc/latencystats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3630?
CVE-2015-3630 has been classified as having a moderate severity due to its potential for privilege escalation and information disclosure.
How do I fix CVE-2015-3630?
To fix CVE-2015-3630, upgrade Docker Engine to version 1.6.1 or later.
What can be exploited using CVE-2015-3630?
CVE-2015-3630 allows local users to modify the host and obtain sensitive information through weak permissions on specific /proc directories.
Which Docker versions are affected by CVE-2015-3630?
CVE-2015-3630 affects Docker Engine versions up to and including 1.6.0.
Is CVE-2015-3630 a local or remote vulnerability?
CVE-2015-3630 is a local vulnerability that requires an attacker to have access to the host system.