CVE-2016-3697
01.06.2016, 20:59
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.Enginsight
Vendor | Product | Version |
---|---|---|
docker | docker | 𝑥 ≤ 1.11.1 |
linuxfoundation | runc | 𝑥 ≤ 0.0.9 |
opensuse | opensuse | 13.2 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
docker.io |
| ||||||||||||
runc |
|

Ubuntu Releases
Common Weakness Enumeration
References