CVE-2016-7569

EUVD-2016-8422
Directory traversal vulnerability in docker2aci before 0.13.0 allows remote attackers to write to arbitrary files via a .. (dot dot) in the embedded layer data in an image.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
Affected Products (NVD)
VendorProductVersion
docker2aci_projectdocker2aci
𝑥
≤ 0.12.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-github-appc-docker2aci
bullseye
0.17.2+dfsg-2.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-github-appc-docker2aci
artful
ignored
bionic
not-affected
cosmic
ignored
disco
ignored
eoan
ignored
focal
needed
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needed
kinetic
dne
lunar
dne
mantic
dne
noble
dne
precise
dne
trusty
dne
xenial
dne
yakkety
ignored
zesty
ignored