CVE-2018-15664

NameCVE-2018-15664
DescriptionIn Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen filesystem (or from within a chroot).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: local)
Debian Bugs929662

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
docker.io (PTS)buster18.09.1+dfsg1-7.1fixed
buster (security)18.09.1+dfsg1-7.1+deb10u1fixed
bullseye, sid18.09.9+dfsg1-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
docker.iosource(unstable)18.09.1+dfsg1-7.1medium929662

Notes

https://www.openwall.com/lists/oss-security/2019/05/28/1
https://github.com/moby/moby/pull/39252

Search for package or bug name: Reporting problems