Vulnerability Name:

CVE-2016-8867 (CCN-118492)

Assigned:2016-10-28
Published:2016-10-28
Updated:2017-07-28
Summary:Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:C/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): None
Vulnerability Type:CWE-264
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2016-8867

Source: BID
Type: Third Party Advisory, VDB Entry
94228

Source: CCN
Type: BID-94228
Docker CVE-2016-8867 Security Bypass Vulnerability

Source: SECTRACK
Type: UNKNOWN
1037203

Source: XF
Type: UNKNOWN
docker-engine-cve20168867-sec-bypass(118492)

Source: CCN
Type: Docker Web site
Incorrect application of ambient capabilities

Source: CONFIRM
Type: Vendor Advisory
https://www.docker.com/docker-cve-database

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2016-8867

Vulnerable Configuration:Configuration 1:
  • cpe:/a:docker:docker:1.12.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:docker:engine:1.12.2:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20168867
    V
    CVE-2016-8867
    2023-06-22
    oval:org.opensuse.security:def:7853
    P
    docker-20.10.23_ce-150000.175.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:604
    P
    Security update for virt-v2v (Moderate) (in QA)
    2022-09-05
    oval:org.opensuse.security:def:602
    P
    Security update for mariadb (Important)
    2022-07-27
    oval:org.opensuse.security:def:3243
    P
    libpython3_6m1_0-3.6.8-2.13 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94873
    P
    docker-20.10.12_ce-159.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:933
    P
    Security update for python-PyJWT (Important) (in QA)
    2022-06-21
    oval:org.opensuse.security:def:931
    P
    Security update for apache2 (Important) (in QA)
    2022-06-14
    oval:org.opensuse.security:def:939
    P
    Security update for wireshark (Moderate)
    2022-02-14
    oval:org.opensuse.security:def:112162
    P
    docker-1.12.3-4.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:70024
    P
    Security update for go1.17 (Moderate)
    2021-12-23
    oval:org.opensuse.security:def:100701
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:1295
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3) (Important)
    2021-12-15
    oval:org.opensuse.security:def:1287
    P
    Security update for the Linux Kernel (Live Patch 9 for SLE 15 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:93988
    P
    (Important)
    2021-12-01
    oval:org.opensuse.security:def:55273
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-11-23
    oval:org.opensuse.security:def:1281
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:1279
    P
    Security update for the Linux Kernel (Live Patch 6 for SLE 15 SP3) (Important)
    2021-11-17
    oval:org.opensuse.security:def:55956
    P
    Security update for glibc (Moderate)
    2021-10-06
    oval:org.opensuse.security:def:105697
    P
    docker-1.12.3-4.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:71202
    P
    grub2-2.02-24.12 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:38202
    P
    Security update for libcroco (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:69919
    P
    Security update for openssl-1_1 (Important)
    2021-08-24
    oval:org.opensuse.security:def:48184
    P
    libqt4-32bit-4.8.7-8.8.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47138
    P
    python-pyOpenSSL-16.0.0-2.3.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47824
    P
    mailman-2.1.17-1.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13876
    P
    libXp6-1.0.2-3.57 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48282
    P
    python-doc-2.7.13-28.31.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47454
    P
    openvswitch-2.7.0-2.29 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48124
    P
    libical1-1.0.1-16.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48351
    P
    xscreensaver-5.22-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47584
    P
    cups-1.7.5-20.17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14068
    P
    xorg-x11-server-7.6_1.18.3-57.34 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13812
    P
    ecryptfs-utils-103-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48186
    P
    libraptor2-0-2.0.10-3.63 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47140
    P
    python-requests-2.8.1-6.11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14013
    P
    procmail-3.22-267.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47826
    P
    mariadb-10.2.18-1.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48249
    P
    openssh-7.2p2-74.45.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47259
    P
    gd-2.1.0-23.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48038
    P
    gv-3.7.4-1.36 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47123
    P
    perl-Config-IniFiles-2.82-3.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13895
    P
    libecpg6-9.4.9-14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48353
    P
    yast2-core-3.3.1-1.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47586
    P
    cups-pk-helper-0.2.5-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14741
    P
    procmail-3.22-269.3.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47124
    P
    perl-HTML-Parser-3.71-1.145 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14719
    P
    p7zip-9.20.1-7.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47676
    P
    libXfont1-1.5.1-11.3.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14081
    P
    apache-commons-daemon-1.0.15-6.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13859
    P
    kernel-default-4.4.21-69.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48251
    P
    opie-2.4-724.56 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47261
    P
    gdk-pixbuf-loader-rsvg-2.40.15-4.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48040
    P
    gzip-1.10-2.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47125
    P
    perl-LWP-Protocol-https-6.04-5.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48280
    P
    python-cryptography-1.3.1-7.13.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47452
    P
    openssh-7.2p2-69.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14057
    P
    wireshark-1.12.13-31.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48122
    P
    libhivex0-1.3.10-4.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47126
    P
    perl-Tk-804.031-3.76 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13988
    P
    ntp-4.2.8p8-14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47678
    P
    libXi6-1.7.4-17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:62384
    P
    docker-19.03.15_ce-6.46.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101128
    P
    docker-19.03.15_ce-6.46.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71089
    P
    python2-salt-2018.3.0-3.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13714
    P
    radvd-1.9.7-2.17 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13722
    P
    shim-0.9-2.14 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13744
    P
    vsftpd-3.0.2-24.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64502
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:67749
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15) (Important)
    2021-04-07
    oval:org.opensuse.security:def:55133
    P
    Security update for xen (Moderate)
    2020-12-22
    oval:org.opensuse.security:def:116925
    P
    docker-19.03.5_ce-6.31.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62368
    P
    docker-17.09.1_ce-4.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:89846
    P
    docker-18.09.1_ce-6.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62370
    P
    docker-18.09.1_ce-6.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103501
    P
    docker-18.09.1_ce-6.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62376
    P
    docker-19.03.5_ce-6.31.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107367
    P
    docker-19.03.5_ce-6.31.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:56241
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49318
    P
    python3-salt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55110
    P
    ft2demos on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38509
    P
    update-alternatives on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49372
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37817
    P
    gzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66576
    P
    opensc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55111
    P
    fuse on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38362
    P
    libraptor2-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37721
    P
    SuSEfirewall2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55790
    P
    Security update for xerces-c (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66668
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73359
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49320
    P
    python3-urllib3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37722
    P
    aaa_base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73241
    P
    libvorbis-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38112
    P
    zypper on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56553
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55511
    P
    Security update for qemu (Important)
    2020-12-01
    oval:org.opensuse.security:def:49374
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56349
    P
    Security update for ecryptfs-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38537
    P
    aaa_base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67849
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37954
    P
    librelp0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56441
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:38421
    P
    nmap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49326
    P
    rsyslog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49380
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38470
    P
    rpcbind on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37733
    P
    apache2-mod_perl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39219
    P
    libwpd-0_10-10 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56634
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55684
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39261
    P
    Security update for Docker and dependencies (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64415
    P
    logrotate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38581
    P
    dovecot22 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38055
    P
    rsync on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56515
    P
    Security update for poppler (Moderate)
    2020-12-01
    BACK
    docker docker 1.12.2
    docker engine 1.12.2 -