DirectorySecurity Advisories
Sign In
Security Advisories

CGA-xvxp-4fwf-9gc6

Published

Last updated

https://images.chainguard.dev/security/CGA-xvxp-4fwf-9gc6
Package

runc

Latest Update
Not affected
Aliases
  • CVE-2016-3697
  • GHSA-q3j5-32m5-58c2

Severity

7.8

High

CVSS V3

Summary

Privilege Elevation in runc

Description

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images