First published: Mon Jul 29 2019(Updated: )
docker-credential-helpers before 0.6.3 has a double free in the List functions.
Credit: josh@bress.net josh@bress.net
Affected Software | Affected Version | How to fix |
---|---|---|
debian/golang-github-docker-docker-credential-helpers | 0.6.3-1 0.6.4+ds1-1 | |
Docker Credential Helpers | <0.6.3 | |
Fedora | =32 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.04 |
https://github.com/docker/docker-credential-helpers/commit/1c9f7ede70a5ab9851f4c9cb37d317fd89cd318a
https://github.com/docker/docker-credential-helpers/commit/87c80bfba583eadc087810d17aa631ef4e405efc
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1020014 is classified as a moderate severity vulnerability due to the potential for double free errors.
CVE-2019-1020014 affects docker-credential-helpers versions prior to 0.6.3.
To fix CVE-2019-1020014, upgrade docker-credential-helpers to version 0.6.3 or later.
CVE-2019-1020014 impacts multiple operating systems including specific versions of Debian, Fedora, and Ubuntu.
CVE-2019-1020014 involves a double free vulnerability in the List functions of the affected software.