CVE-2015-3630

Publication date 18 May 2015

Last updated 24 July 2024


Ubuntu priority

Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.

Status

Package Ubuntu Release Status
docker.io 17.04 zesty
Not affected
16.10 yakkety Ignored end of life
16.04 LTS xenial
Fixed 1.6.2~dfsg1-1ubuntu4
15.10 wily Ignored end of life
15.04 vivid Ignored end of life
14.10 utopic Ignored end of life
14.04 LTS trusty
Fixed 1.6.2~dfsg1-1ubuntu4~14.04.1
12.04 LTS precise Not in release