Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 729208 (CVE-2020-13401) - <app-emulation/docker-19.03.12: Address spoofing vulnerability (CVE-2020-13401)
Summary: <app-emulation/docker-19.03.12: Address spoofing vulnerability (CVE-2020-13401)
Status: RESOLVED FIXED
Alias: CVE-2020-13401
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL: https://github.com/docker/docker-ce/r...
Whiteboard: B3 [glsa+ cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-06-22 22:17 UTC by Sam James
Modified: 2020-08-26 21:44 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-22 22:17:58 UTC
Description:
"An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service."
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-22 22:18:21 UTC
Please bump to 19.03.11.
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-18 20:58:46 UTC
ping
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-26 05:54:27 UTC
ping. Please bump to 19.03.11.
Comment 4 Larry the Git Cow gentoo-dev 2020-08-01 19:17:53 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7dbf23f4a87e5e05138d5f348bf26f2407518d89

commit 7dbf23f4a87e5e05138d5f348bf26f2407518d89
Author:     William Hubbs <williamh@gentoo.org>
AuthorDate: 2020-08-01 19:13:07 +0000
Commit:     William Hubbs <williamh@gentoo.org>
CommitDate: 2020-08-01 19:16:17 +0000

    app-emulation/docker: 19.03.12 security bump
    
    Bug: https://bugs.gentoo.org/729208
    Signed-off-by: William Hubbs <williamh@gentoo.org>

 app-emulation/docker/Manifest               |   1 +
 app-emulation/docker/docker-19.03.12.ebuild | 314 ++++++++++++++++++++++++++++
 2 files changed, 315 insertions(+)
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-01 19:56:43 UTC
Thanks, please cleanup <19.03.12 when ready!
Comment 6 Larry the Git Cow gentoo-dev 2020-08-22 21:17:23 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c36679efd436befb08ce71b20194a55c1f4de0b5

commit c36679efd436befb08ce71b20194a55c1f4de0b5
Author:     William Hubbs <williamh@gentoo.org>
AuthorDate: 2020-08-22 21:15:58 +0000
Commit:     William Hubbs <williamh@gentoo.org>
CommitDate: 2020-08-22 21:16:15 +0000

    app-emulation/docker: remove old
    
    Bug: https://bugs.gentoo.org/729208
    Signed-off-by: William Hubbs <williamh@gentoo.org>

 app-emulation/docker/Manifest              |   1 -
 app-emulation/docker/docker-19.03.8.ebuild | 314 -----------------------------
 2 files changed, 315 deletions(-)
Comment 7 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-08-23 00:30:45 UTC
Thanks.
Comment 8 GLSAMaker/CVETool Bot gentoo-dev 2020-08-26 21:44:04 UTC
This issue was resolved and addressed in
 GLSA 202008-15 at https://security.gentoo.org/glsa/202008-15
by GLSA coordinator Sam James (sam_c).