Summary: | <app-emulation/docker-17.12.1: Data loss vulnerability (CVE-2017-16539) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | GLSAMaker/CVETool Bot <glsamaker> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | CC: | admwiggin, mrueg, williamh |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://github.com/moby/moby/pull/35399 | ||
Whiteboard: | C4 [noglsa cve] | ||
Package list: | Runtime testing required: | --- |
Description
GLSAMaker/CVETool Bot
![]() @Maintainers could you please confirm if we are affected? I see 17.06.2 also stable, maybe we just need to clean 17.03? Thank you 17.03 is unsupported upstream, so removing probably makes sense. Same goes for 17.06, though. This was fixed in 17.09 via https://github.com/docker/docker-ce/pull/291 (but the change doesn't appear to be in an actual 17.09 release yet, just the staging branch for the release). The same goes for 17.11 via https://github.com/docker/docker-ce/pull/290 (but with the same caveat that it appears it never went out with an actual release). So, the only official releases which actually contain this fix are the release candidates for 17.12, currently. 17.12.1 contains the patch per the upstream commit on: https://github.com/docker/docker-ce/pull/290 GLSA Vote: No @maintainers, please clean the vulnerable version. |