VDB
Sign up
HIGH7.3

GHSA-5qgp-p5jc-w2rm

Arbitrary Code Execution in Docker

Quick fix

GHSA-5qgp-p5jc-w2rm — github.com/docker/docker: upgrade to the fixed version with the command below.

go get github.com/docker/docker@v1.3.2

Details

Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/docker/docker
Introduced in: 0Fixed in: 1.3.2
Fixgo get github.com/docker/docker@v1.3.2

References