Docker·ûºÅÁ´½ÓÌõ¼þ¾ºÕùÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-06-03Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-15664£¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬CVSS·ÖÖµ£º8.7
ÊÜÓ°ÏìµÄ°æ±¾
Docker 18.06.1-ce-rc2¼°Ö®Ç°°æ±¾
Îó²î¸ÅÊö
DockerÊÇÃÀ¹úDocker¹«Ë¾µÄÒ»¿î¿ªÔ´µÄÓ¦ÓÃÈÝÆ÷ÒýÇæ¡£¸Ã²úÆ·Ö§³ÖÔÚLinuxϵͳÉϽ¨ÉèÒ»¸öÈÝÆ÷£¨ÇáÁ¿¼¶ÐéÄâ»ú£©²¢°²ÅźÍÔËÐÐÓ¦ÓóÌÐò£¬ÒÔ¼°Í¨¹ýÉèÖÃÎļþʵÏÖÓ¦ÓóÌÐòµÄ×Ô¶¯»¯×°Öᢰ²ÅźÍÉý¼¶¡£
Docker 18.06.1-ce-rc2¼°Ö®Ç°°æ±¾ÖеÄAPI¶Ëµã±£´æ·ûºÅÁ´½ÓÌõ¼þ¾ºÕùÎó²î¡£¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úƷδÄÜ׼ȷµØ¹ýÂË×ÊÔ´»òÎļþ·¾¶ÖеÄÌØÊâÔªËØ¡£¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸¶¨µÄ³ÌÐò¶Ô×ÊÔ´¾ÙÐвÙ×÷֮ǰÐÞ¸Ä×ÊԴ·¾¶£¬´Ó¶ø¿ÉÄÜ»ñµÃí§ÒâÎļþµÄ¶Áд»á¼ûȨÏÞ£¬Õâ±»³ÆÎªTOCTOUÀàÐ͵Äbug¡£¸ÃÎó²îµÄ½¹µãÔ´ÓÚFollowSymlinkInScope¹¦Ð§Ò×ÊÜTOCTOU¹¥»÷¡£
Îó²îÑéÖ¤
Îó²îPOC£ºhttps://seclists.org/oss-sec/2019/q2/131¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥½â¾ö´ËÇå¾²ÎÊÌ⣬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö²½·¥£ºhttps://www.docker.com/ ¡£
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ