MGASA-2020-0406 - Updated docker packages fix a security vulnerability

Publication date: 09 Nov 2020
URL: https://advisories.mageia.org/MGASA-2020-0406.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-15157

It was discovered that Docker could be made to expose sensitive information
when processing URLs in container image manifests. A remote attacker could use
this to trick the user and obtain the user's registry credentials
(CVE-2020-15157).

References:
- https://bugs.mageia.org/show_bug.cgi?id=27437
- https://www.openwall.com/lists/oss-security/2020/10/15/1
- https://ubuntu.com/security/notices/USN-4589-2
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15157

SRPMS:
- 7/core/docker-18.09.9-1.2.mga7

Mageia 2020-0406: docker security update

It was discovered that Docker could be made to expose sensitive information when processing URLs in container image manifests

Summary

It was discovered that Docker could be made to expose sensitive information when processing URLs in container image manifests. A remote attacker could use this to trick the user and obtain the user's registry credentials (CVE-2020-15157).

References

- https://bugs.mageia.org/show_bug.cgi?id=27437

- https://www.openwall.com/lists/oss-security/2020/10/15/1

- https://ubuntu.com/security/notices/USN-4589-2

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15157

Resolution

MGASA-2020-0406 - Updated docker packages fix a security vulnerability

SRPMS

- 7/core/docker-18.09.9-1.2.mga7

Severity
Publication date: 09 Nov 2020
URL: https://advisories.mageia.org/MGASA-2020-0406.html
Type: security
CVE: CVE-2020-15157

Related News