Docker·ûºÅÁ´½ÓǰÌᾺÕù·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-06-03·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-15664£¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬CVSS·ÖÖµ£º8.7
ÊÜÓ°ÏìµÄ°æ±¾
Docker 18.06.1-ce-rc2¼°Ö®Ç°°æ±¾
·ì϶¸ÅÊö
DockerÊÇÃÀ¹úDocker¹«Ë¾µÄÒ»¿î¿ªÔ´µÄÀûÓÃÈÝÆ÷ÒýÇæ¡£¸Ã²úÆ·Ö§³ÖÔÚLinuxϵͳÉÏ´´½¨Ò»¸öÈÝÆ÷£¨ÇáÁ¿¼¶Ðé¹¹»ú£©²¢²¿ÊðºÍÔËÐÐÀûÓ÷¨Ê½£¬ÒÔ¼°Í¨¹ýÅäÖÃÎļþʵÏÖÀûÓ÷¨Ê½µÄ×Ô¶¯°ç×°Öᢲ¿ÊðºÍÉý¼¶¡£
Docker 18.06.1-ce-rc2¼°Ö®Ç°°æ±¾ÖеÄAPI¶Ëµã´æÔÚ·ûºÅÁ´½ÓǰÌᾺÕù·ì϶¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úƷδÄÜÕýÈ·µØ¹ýÂË×ÊÔ´»òÎļþõè¾¶ÖеÄÌØÊâÔªËØ¡£¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸¶¨µÄ·¨Ê½¶Ô×ÊÔ´½øÐвÙ×÷֮ǰÅú¸Ä×ÊÔ´õè¾¶£¬´Ó¶ø¿ÉÄÜ»ñµÃËÁÒâÎļþµÄ¶Áд½Ó¼ûȨÏÞ£¬Õâ±»³ÆÎªTOCTOUÀàÐ͵Äbug¡£¸Ã·ì϶µÄÖ÷ÌâÔ´ÓÚFollowSymlinkInScopeÖ°ÄÜÒ×ÊÜTOCTOU¹¥»÷¡£
·ì϶ÑéÖ¤
·ì϶POC£ºhttps://seclists.org/oss-sec/2019/q2/131¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©½â¾ö´Ë°²È«ÎÊÌ⣬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö·¨×Ó£ºhttps://www.docker.com/ ¡£
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ