Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2014-12-12T15:00:00
Updated: 2024-08-06T12:17:23.673Z
Reserved: 2014-09-15T00:00:00
Link: CVE-2014-6407
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2014-12-12T15:59:04.337
Modified: 2014-12-15T19:36:08.617
Link: CVE-2014-6407
Redhat