First published: Thu Oct 15 2020(Updated: )
USN-4589-1 fixed a vulnerability in containerd. This update provides the corresponding update for docker.io. Original advisory details: It was discovered that containerd could be made to expose sensitive information when processing URLs in container image manifests. A remote attacker could use this to trick the user and obtain the user's registry credentials.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/docker.io | <19.03.8-0ubuntu1.20.04.1 | 19.03.8-0ubuntu1.20.04.1 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/docker.io | <19.03.6-0ubuntu1~18.04.2 | 19.03.6-0ubuntu1~18.04.2 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/docker.io | <18.09.7-0ubuntu1~16.04.6 | 18.09.7-0ubuntu1~16.04.6 |
Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Docker vulnerability is USN-4589-2.
The affected version of docker.io for Ubuntu 20.04 is 19.03.8-0ubuntu1.20.04.1.
The affected version of docker.io for Ubuntu 18.04 is 19.03.6-0ubuntu1~18.04.2.
The affected version of docker.io for Ubuntu 16.04 is 18.09.7-0ubuntu1~16.04.6.
The severity of the Docker vulnerability is not specified in the provided information.