Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 2019-0269 Critical: Docker Double Free Denial Of Service

mageia
Calendar Grey September 12, 2019
Dist Mageia Esm H88
Revised container tools resolve significant security vulnerability found by Elaine Jones, endangering platform integrity and protection.
Updated docker packages fix security vulnerability: Jasiel Spelman discovered that a double free existed in the docker-credential-helpers bundled in Docker

Summary

Updated docker packages fix security vulnerability:
Jasiel Spelman discovered that a double free existed in the docker-credential-helpers bundled in Docker. A local attacker could use this to cause a denial of service (crash) or possibly execute arbitrary code (CVE-2019-1020014).

References

- https://bugs.mageia.org/show_bug.cgi?id=25374

- https://ubuntu.com/security/notices/USN-4103-2

- https://www.cve.org/CVERecord?id=CVE-2019-1020014

Resolution

SRPMS

- 6/core/docker-18.06.3-1.2.mga6

- 7/core/docker-18.09.8-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 12 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0269.html
Type: security
CVE: CVE-2019-1020014

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here