CVE-2017-7412: High severity NixOS NixOS vulnerability
Published Apr 4, 2017
·Updated
NixOS 17.03 before 17.03.887 has a world-writable Docker socket, which allows local users to gain privileges by executing docker commands.
Affected Software
1 affected component
NixOS NixOS=17.03
Remediation
Event History
Apr 4, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:59 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7412?
CVE-2017-7412 is classified as having a high severity level due to its potential for privilege escalation.
2
How do I fix CVE-2017-7412?
To fix CVE-2017-7412, ensure that the Docker socket has appropriate permissions, restricting it from being world-writable.
3
Who is affected by CVE-2017-7412?
CVE-2017-7412 affects users running NixOS version 17.03 prior to the update 17.03.887.
4
What are the potential impacts of CVE-2017-7412?
The potential impacts of CVE-2017-7412 include unauthorized access and control over Docker containers, leading to local privilege escalation.
5
Is CVE-2017-7412 a local or remote vulnerability?
CVE-2017-7412 is a local vulnerability, as it requires an attacker to have local access to the system.