Total vulnerabilities in the database
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
Software | From | Fixed in |
---|---|---|
docker / docker | - | 1.11.1.x |
linuxfoundation / runc | - | 0.0.9.x |
opensuse / opensuse | 13.2 | 13.2.x |
![]() |
- | 0.1.0 |