/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2016-3697

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2016-3697

CGA ID

CGA-xvxp-4fwf-9gc6

Severity

7.8

High

CVSS V3

Description

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images