Vulnerability Name:

CVE-2014-9356 (CCN-99308)

Assigned:2014-12-11
Published:2014-12-11
Updated:2019-12-11
Summary:Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.
CVSS v3 Severity:8.6 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:8.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:C/A:P)
6.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:C/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-22
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2014-9356

Source: CCN
Type: oss-security Mailing List, Thu 11 Dec 2014
Docker 1.3.3 - Security Advisory [11 Dec 2014]

Source: CCN
Type: IBM Security Bulletin 1693356
Vulnerability in Docker affected IBM Workflow for Bluemix (CVE-2014-6407, CVE-2014-9356, CVE-2014-9358)

Source: BUGTRAQ
Type: Broken Link
20141212 Docker 1.3.3 - Security Advisory [11 Dec 2014]

Source: CCN
Type: BID-71654
Docker CVE-2014-9356 Multiple Directory Traversal Vulnerabilities

Source: MISC
Type: Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1172761

Source: CCN
Type: Docker Web site
Release Notes

Source: XF
Type: UNKNOWN
docker-cve20149356-dir-traversal(99308)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:docker:docker:*:*:*:*:*:*:*:* (Version < 1.3.3)

  • Configuration CCN 1:
  • cpe:/a:docker:docker:1.3.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20149356
    V
    CVE-2014-9356
    2023-06-22
    oval:org.opensuse.security:def:7703
    P
    libxslt-devel-1.1.34-150400.3.3.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7853
    P
    docker-20.10.23_ce-150000.175.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7725
    P
    openslp-2.0.0-6.15.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:604
    P
    Security update for virt-v2v (Moderate) (in QA)
    2022-09-05
    oval:org.opensuse.security:def:602
    P
    Security update for mariadb (Important)
    2022-07-27
    oval:org.opensuse.security:def:3243
    P
    libpython3_6m1_0-3.6.8-2.13 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94873
    P
    docker-20.10.12_ce-159.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:933
    P
    Security update for python-PyJWT (Important) (in QA)
    2022-06-21
    oval:org.opensuse.security:def:931
    P
    Security update for apache2 (Important) (in QA)
    2022-06-14
    oval:org.opensuse.security:def:939
    P
    Security update for wireshark (Moderate)
    2022-02-14
    oval:org.opensuse.security:def:112162
    P
    docker-1.12.3-4.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:70024
    P
    Security update for go1.17 (Moderate)
    2021-12-23
    oval:org.opensuse.security:def:100701
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:1295
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3) (Important)
    2021-12-15
    oval:org.opensuse.security:def:1287
    P
    Security update for the Linux Kernel (Live Patch 9 for SLE 15 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:19520
    P
    Security update for the Linux Kernel (Important)
    2021-12-06
    oval:org.opensuse.security:def:93988
    P
    (Important)
    2021-12-01
    oval:org.opensuse.security:def:1281
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:1279
    P
    Security update for the Linux Kernel (Live Patch 6 for SLE 15 SP3) (Important)
    2021-11-17
    oval:org.opensuse.security:def:6976
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 15 SP1) (Important)
    2021-10-14
    oval:org.opensuse.security:def:105697
    P
    docker-1.12.3-4.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:71202
    P
    grub2-2.02-24.12 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:69919
    P
    Security update for openssl-1_1 (Important)
    2021-08-24
    oval:org.opensuse.security:def:48251
    P
    opie-2.4-724.56 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48186
    P
    libraptor2-0-2.0.10-3.63 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48122
    P
    libhivex0-1.3.10-4.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48038
    P
    gv-3.7.4-1.36 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47824
    P
    mailman-2.1.17-1.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47676
    P
    libXfont1-1.5.1-11.3.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47125
    P
    perl-LWP-Protocol-https-6.04-5.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47584
    P
    cups-1.7.5-20.17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47452
    P
    openssh-7.2p2-69.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47259
    P
    gd-2.1.0-23.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47138
    P
    python-pyOpenSSL-16.0.0-2.3.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47124
    P
    perl-HTML-Parser-3.71-1.145 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48124
    P
    libical1-1.0.1-16.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48040
    P
    gzip-1.10-2.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47826
    P
    mariadb-10.2.18-1.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47678
    P
    libXi6-1.7.4-17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47586
    P
    cups-pk-helper-0.2.5-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47454
    P
    openvswitch-2.7.0-2.29 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47261
    P
    gdk-pixbuf-loader-rsvg-2.40.15-4.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47140
    P
    python-requests-2.8.1-6.11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47126
    P
    perl-Tk-804.031-3.76 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48351
    P
    xscreensaver-5.22-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48280
    P
    python-cryptography-1.3.1-7.13.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48249
    P
    openssh-7.2p2-74.45.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48184
    P
    libqt4-32bit-4.8.7-8.8.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47123
    P
    perl-Config-IniFiles-2.82-3.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48353
    P
    yast2-core-3.3.1-1.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48282
    P
    python-doc-2.7.13-28.31.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:101128
    P
    docker-19.03.15_ce-6.46.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62384
    P
    docker-19.03.15_ce-6.46.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:55227
    P
    Security update for libsndfile (Critical)
    2021-08-05
    oval:org.opensuse.security:def:36533
    P
    pango-devel-1.26.2-1.3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36491
    P
    libsss_idmap-devel-1.9.4-0.16.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71089
    P
    python2-salt-2018.3.0-3.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:55910
    P
    Security update for libX11 (Important)
    2021-06-08
    oval:org.opensuse.security:def:6901
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15 SP1) (Important)
    2021-05-25
    oval:org.opensuse.security:def:64502
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:6882
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15 SP1) (Important)
    2021-04-28
    oval:org.opensuse.security:def:6867
    P
    Security update for the Linux Kernel (Live Patch 13 for SLE 15 SP1) (Important)
    2021-04-07
    oval:org.opensuse.security:def:67749
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15) (Important)
    2021-04-07
    oval:org.opensuse.security:def:7065
    P
    Security update for the Linux Kernel (Live Patch 8 for SLE 15 SP2) (Important)
    2021-04-07
    oval:org.opensuse.security:def:7001
    P
    Security update for the Linux Kernel (Live Patch 11 for SLE 15 SP1) (Important)
    2021-02-10
    oval:org.opensuse.security:def:40079
    P
    Security update for cups (Moderate)
    2021-02-02
    oval:org.opensuse.security:def:41031
    P
    Security update for xen (Important)
    2020-12-09
    oval:org.opensuse.security:def:7052
    P
    Security update for the Linux Kernel (Live Patch 4 for SLE 15 SP2) (Important)
    2020-12-07
    oval:org.opensuse.security:def:62368
    P
    docker-17.09.1_ce-4.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13234
    P
    docker-1.8.3-52.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35853
    P
    MozillaFirefox-17.0.4esr-0.10.42 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35809
    P
    postgresql-8.3.14-0.2.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35781
    P
    lvm2-2.02.84-3.25.5 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:89846
    P
    docker-18.09.1_ce-6.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35742
    P
    libcgroup1-0.34-2.5.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103501
    P
    docker-18.09.1_ce-6.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62370
    P
    docker-18.09.1_ce-6.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:46353
    P
    docker-1.6.2-31.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35693
    P
    evolution-data-server-2.28.2-0.26.33.14 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107367
    P
    docker-19.03.5_ce-6.31.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35634
    P
    qt3-3.3.8b-88.21 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62376
    P
    docker-19.03.5_ce-6.31.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:46354
    P
    docker-1.8.3-52.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13233
    P
    docker-1.6.2-31.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116925
    P
    docker-19.03.5_ce-6.31.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:40090
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:49318
    P
    python3-salt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6820
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67849
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6774
    P
    libvirglrenderer0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6752
    P
    libreoffice on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66576
    P
    opensc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6744
    P
    libproxy1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18788
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:56588
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18755
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56507
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49380
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18643
    P
    Security update for systemd (Important)
    2020-12-01
    oval:org.opensuse.security:def:56469
    P
    Security update for xerces-j2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73359
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18605
    P
    Security update for php7 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56395
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49320
    P
    python3-urllib3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34994
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:18571
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18513
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:18427
    P
    Security update for expat (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40980
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 12 SP2) (Important)
    2020-12-01
    oval:org.opensuse.security:def:41714
    P
    Security update for docker (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18392
    P
    Security update for openslp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40951
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:55064
    P
    avahi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40906
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:18384
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:35474
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35384
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7043
    P
    libgnomesu on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49326
    P
    rsyslog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40078
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:35327
    P
    Security update for microcode_ctl (Important)
    2020-12-01
    oval:org.opensuse.security:def:56303
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:35226
    P
    Security update for lzo
    2020-12-01
    oval:org.opensuse.security:def:56195
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:35090
    P
    Security update for kdebase4-workspace (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49372
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35006
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55744
    P
    Security update for xfsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34995
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:55638
    P
    Security update for gpg2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:41669
    P
    Security update for libarchive (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55465
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:40854
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:73241
    P
    libvorbis-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40790
    P
    Security update for MozillaFirefox, mozilla-nspr and mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:18882
    P
    Security update for postgresql10 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66668
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55087
    P
    cvs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40614
    P
    Security update for log4j (Important)
    2020-12-01
    oval:org.opensuse.security:def:18858
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:19546
    P
    Security update for docker (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55065
    P
    bash on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40512
    P
    Security update for bash (Important)
    2020-12-01
    oval:org.opensuse.security:def:18846
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:64415
    P
    logrotate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40443
    P
    Security update for libssh2_org (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7034
    P
    libexif12 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40334
    P
    Security update for binutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40182
    P
    Security update for Linux Kernel Live Patch 21 for SLE 12 SP1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:49374
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.xenial:def:201493560000000
    V
    CVE-2014-9356 on Ubuntu 16.04 LTS (xenial) - high.
    2019-12-02
    oval:com.ubuntu.trusty:def:20149356000
    V
    CVE-2014-9356 on Ubuntu 14.04 LTS (trusty) - high.
    2014-12-16
    oval:com.ubuntu.xenial:def:20149356000
    V
    CVE-2014-9356 on Ubuntu 16.04 LTS (xenial) - high.
    2014-12-16
    BACK
    docker docker *
    docker docker 1.3.2