VDB
Sign up
CRITICAL9.8

GHSA-997c-fj8j-rq5h

Arbitrary Code Execution

Quick fix

GHSA-997c-fj8j-rq5h — github.com/docker/docker: upgrade to the fixed version with the command below.

go get github.com/docker/docker@v1.3.3

Details

Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the chroot for archive extraction.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/docker/docker
Introduced in: 0Fixed in: 1.3.3
Fixgo get github.com/docker/docker@v1.3.3

References