Vulnerability Name:

CVE-2016-3697 (CCN-113791)

Assigned:2016-03-30
Published:2016-03-30
Updated:2021-01-05
Summary:libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.4 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-264
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2016-3697

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2016:1417

Source: CCN
Type: RHSA-2016-1034
Moderate: docker security, bug fix, and enhancement update

Source: REDHAT
Type: Third Party Advisory
RHSA-2016:1034

Source: CCN
Type: RHSA-2016-2634
Moderate: docker security and bug fix update

Source: REDHAT
Type: Third Party Advisory
RHSA-2016:2634

Source: CCN
Type: IBM Security Bulletin 2004947 (Security QRadar SIEM)
Docker and Python as used in IBM QRadar SIEM is vulnerable to various CVEs.

Source: CCN
Type: Docker Web site
Docker

Source: XF
Type: UNKNOWN
docker-cve20163697-priv-esc(113791)

Source: CONFIRM
Type: Patch, Third Party Advisory
https://github.com/docker/docker/issues/21436

Source: CONFIRM
Type: Third Party Advisory
https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091

Source: CONFIRM
Type: Third Party Advisory
https://github.com/opencontainers/runc/pull/708

Source: CONFIRM
Type: Patch, Third Party Advisory
https://github.com/opencontainers/runc/releases/tag/v0.1.0

Source: GENTOO
Type: Third Party Advisory
GLSA-201612-28

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2016-3697

Vulnerable Configuration:Configuration 1:
  • cpe:/a:docker:docker:*:*:*:*:*:*:*:* (Version <= 1.11.1)

  • Configuration 2:
  • cpe:/a:linuxfoundation:runc:*:*:*:*:*:*:*:* (Version <= 0.0.9)

  • Configuration 3:
  • cpe:/o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:docker:docker:1.11.2:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:qradar_security_information_and_event_manager:7.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20163697
    V
    CVE-2016-3697
    2023-06-22
    oval:org.opensuse.security:def:7853
    P
    docker-20.10.23_ce-150000.175.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:604
    P
    Security update for virt-v2v (Moderate) (in QA)
    2022-09-05
    oval:org.opensuse.security:def:602
    P
    Security update for mariadb (Important)
    2022-07-27
    oval:org.opensuse.security:def:3243
    P
    libpython3_6m1_0-3.6.8-2.13 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94873
    P
    docker-20.10.12_ce-159.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:933
    P
    Security update for python-PyJWT (Important) (in QA)
    2022-06-21
    oval:org.opensuse.security:def:931
    P
    Security update for apache2 (Important) (in QA)
    2022-06-14
    oval:org.opensuse.security:def:939
    P
    Security update for wireshark (Moderate)
    2022-02-14
    oval:org.opensuse.security:def:112162
    P
    docker-1.12.3-4.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:38207
    P
    Security update for libsndfile (Important)
    2022-01-05
    oval:org.opensuse.security:def:70024
    P
    Security update for go1.17 (Moderate)
    2021-12-23
    oval:org.opensuse.security:def:100701
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:1295
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3) (Important)
    2021-12-15
    oval:org.opensuse.security:def:38367
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:1287
    P
    Security update for the Linux Kernel (Live Patch 9 for SLE 15 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:93988
    P
    (Important)
    2021-12-01
    oval:org.opensuse.security:def:55277
    P
    Security update for clamav (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:1281
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:1279
    P
    Security update for the Linux Kernel (Live Patch 6 for SLE 15 SP3) (Important)
    2021-11-17
    oval:org.opensuse.security:def:38426
    P
    Security update for SUSE Manager Client Tools (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:55960
    P
    Security update for MozillaFirefox (Important)
    2021-10-15
    oval:org.opensuse.security:def:105697
    P
    docker-1.12.3-4.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:71202
    P
    grub2-2.02-24.12 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:69919
    P
    Security update for openssl-1_1 (Important)
    2021-08-24
    oval:org.opensuse.security:def:48124
    P
    libical1-1.0.1-16.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48351
    P
    xscreensaver-5.22-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47584
    P
    cups-1.7.5-20.17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14073
    P
    zoo-2.10-1020.56 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13817
    P
    expat-2.1.0-17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48186
    P
    libraptor2-0-2.0.10-3.63 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47140
    P
    python-requests-2.8.1-6.11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14018
    P
    python-pyOpenSSL-16.0.0-2.3.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47826
    P
    mariadb-10.2.18-1.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48249
    P
    openssh-7.2p2-74.45.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47259
    P
    gd-2.1.0-23.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48038
    P
    gv-3.7.4-1.36 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47123
    P
    perl-Config-IniFiles-2.82-3.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13900
    P
    libgc1-7.2d-3.75 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48353
    P
    yast2-core-3.3.1-1.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47586
    P
    cups-pk-helper-0.2.5-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14746
    P
    python-imaging-1.1.7-21.15 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47124
    P
    perl-HTML-Parser-3.71-1.145 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14724
    P
    pam_yubico-2.26-1.25 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47676
    P
    libXfont1-1.5.1-11.3.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14086
    P
    apache2-mod_nss-1.0.14-18.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13864
    P
    libIlmImf-Imf_2_1-21-2.1.0-4.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48251
    P
    opie-2.4-724.56 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47261
    P
    gdk-pixbuf-loader-rsvg-2.40.15-4.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48040
    P
    gzip-1.10-2.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47125
    P
    perl-LWP-Protocol-https-6.04-5.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48280
    P
    python-cryptography-1.3.1-7.13.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47452
    P
    openssh-7.2p2-69.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14062
    P
    xf86-video-intel-2.99.917.641_ge4ef6e9-12.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48122
    P
    libhivex0-1.3.10-4.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47126
    P
    perl-Tk-804.031-3.76 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13993
    P
    openvswitch-2.5.1-24.15 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47678
    P
    libXi6-1.7.4-17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48184
    P
    libqt4-32bit-4.8.7-8.8.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47138
    P
    python-pyOpenSSL-16.0.0-2.3.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47824
    P
    mailman-2.1.17-1.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13881
    P
    libXv1-1.0.10-3.56 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48282
    P
    python-doc-2.7.13-28.31.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47454
    P
    openvswitch-2.7.0-2.29 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:62384
    P
    docker-19.03.15_ce-6.46.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101128
    P
    docker-19.03.15_ce-6.46.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:13719
    P
    rtkit-0.11_git201205151338-8.17 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13727
    P
    squidGuard-1.4-23.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13749
    P
    xalan-j2-2.7.0-264.133 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71089
    P
    python2-salt-2018.3.0-3.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64502
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:67749
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15) (Important)
    2021-04-07
    oval:org.opensuse.security:def:38117
    P
    Security update for cyrus-sasl (Important)
    2020-12-17
    oval:org.opensuse.security:def:116925
    P
    docker-19.03.5_ce-6.31.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62368
    P
    docker-17.09.1_ce-4.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:89846
    P
    docker-18.09.1_ce-6.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62370
    P
    docker-18.09.1_ce-6.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103501
    P
    docker-18.09.1_ce-6.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62376
    P
    docker-19.03.5_ce-6.31.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107367
    P
    docker-19.03.5_ce-6.31.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:37822
    P
    ipsec-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66576
    P
    opensc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55115
    P
    gdk-pixbuf-loader-rsvg on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37726
    P
    apache-commons-beanutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55794
    P
    Security update for wget (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66668
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73359
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49320
    P
    python3-urllib3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37727
    P
    apache-commons-daemon on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73241
    P
    libvorbis-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56557
    P
    Security update for libcgroup (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55515
    P
    Security update for tigervnc, fltk (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49374
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56353
    P
    security update for spice-vdagent (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38542
    P
    apache-commons-daemon on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67849
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37959
    P
    libsndfile1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56445
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55137
    P
    gstreamer-plugins-base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49326
    P
    rsyslog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49380
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38475
    P
    rtkit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37738
    P
    automake on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39224
    P
    pidgin-plugin-otr on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56638
    P
    Security update for exempi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55688
    P
    Security update for MozillaFirefox, mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:39266
    P
    Security update for docker (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64415
    P
    logrotate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38586
    P
    elfutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38060
    P
    sane-backends on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56519
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:56245
    P
    Security update for ppp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49318
    P
    python3-salt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55114
    P
    gdk-pixbuf-lang on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38514
    P
    wget on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49372
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.trusty:def:20163697000
    V
    CVE-2016-3697 on Ubuntu 14.04 LTS (trusty) - medium.
    2016-06-01
    oval:com.ubuntu.xenial:def:20163697000
    V
    CVE-2016-3697 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-06-01
    oval:com.ubuntu.xenial:def:201636970000000
    V
    CVE-2016-3697 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-06-01
    BACK
    docker docker *
    linuxfoundation runc *
    opensuse opensuse 13.2
    docker docker 1.11.2
    ibm qradar security information and event manager 7.2