CVE-2018-15664

In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen filesystem (or from within a chroot).
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
LOCAL
HIGH
LOW
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
dockerdocker
17.06.0-ce
dockerdocker
17.06.0-ce:rc1
dockerdocker
17.06.0-ce:rc2
dockerdocker
17.06.0-ce:rc3
dockerdocker
17.06.0-ce:rc4
dockerdocker
17.06.0-ce:rc5
dockerdocker
17.06.1-ce
dockerdocker
17.06.1-ce:rc1
dockerdocker
17.06.1-ce:rc2
dockerdocker
17.06.1-ce:rc3
dockerdocker
17.06.1-ce:rc4
dockerdocker
17.06.2-ce
dockerdocker
17.06.2-ce:rc1
dockerdocker
17.07.0-ce
dockerdocker
17.07.0-ce:rc1
dockerdocker
17.07.0-ce:rc2
dockerdocker
17.07.0-ce:rc3
dockerdocker
17.07.0-ce:rc4
dockerdocker
17.09.0-ce
dockerdocker
17.09.0-ce:rc1
dockerdocker
17.09.0-ce:rc2
dockerdocker
17.09.0-ce:rc3
dockerdocker
17.09.1-ce
dockerdocker
17.09.1-ce-:rc1
dockerdocker
17.10.0-ce
dockerdocker
17.10.0-ce:rc1
dockerdocker
17.10.0-ce:rc2
dockerdocker
17.11.0-ce
dockerdocker
17.11.0-ce:rc1
dockerdocker
17.11.0-ce:rc2
dockerdocker
17.11.0-ce:rc3
dockerdocker
17.11.0-ce:rc4
dockerdocker
17.12.0-ce
dockerdocker
17.12.0-ce:rc1
dockerdocker
17.12.0-ce:rc2
dockerdocker
17.12.0-ce:rc3
dockerdocker
17.12.0-ce:rc4
dockerdocker
17.12.1-ce
dockerdocker
17.12.1-ce:rc1
dockerdocker
17.12.1-ce:rc2
dockerdocker
18.01.0-ce
dockerdocker
18.01.0-ce:rc1
dockerdocker
18.02.0-ce
dockerdocker
18.02.0-ce:rc1
dockerdocker
18.02.0-ce:rc2
dockerdocker
18.03.0-ce
dockerdocker
18.03.0-ce:rc1
dockerdocker
18.03.0-ce:rc2
dockerdocker
18.03.0-ce:rc3
dockerdocker
18.03.0-ce:rc4
dockerdocker
18.03.1-ce
dockerdocker
18.03.1-ce:rc1
dockerdocker
18.03.1-ce:rc2
dockerdocker
18.04.0-ce
dockerdocker
18.04.0-ce:rc1
dockerdocker
18.04.0-ce:rc2
dockerdocker
18.05.0-ce
dockerdocker
18.05.0-ce:rc1
dockerdocker
18.06.0-ce
dockerdocker
18.06.0-ce:rc1
dockerdocker
18.06.0-ce:rc2
dockerdocker
18.06.0-ce:rc3
dockerdocker
18.06.1-ce:rc1
dockerdocker
18.06.1-ce:rc2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
docker.io
bullseye
20.10.5+dfsg1-1+deb11u2
fixed
bullseye (security)
20.10.5+dfsg1-1+deb11u3
fixed
bookworm
20.10.24+dfsg1-1
fixed
sid
26.1.5+dfsg1-4
fixed
trixie
26.1.5+dfsg1-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
docker.io
disco
Fixed 18.09.7-0ubuntu1~19.04.4
released
cosmic
Fixed 18.09.7-0ubuntu1~18.10.3
released
bionic
Fixed 18.09.7-0ubuntu1~18.04.3
released
xenial
Fixed 18.09.7-0ubuntu1~16.04.4
released
trusty
dne