HIGH🇬🇧 English

CVE-2018-9862

CVSS 7.8v3.0pub. 2018-04-09upd. 2024-11-21

util.c in runV 1.0.0 for Docker mishandles a numeric username, which allows attackers to obtain root access by leveraging the presence of an initial numeric value on an /etc/passwd line, and then issuing a "docker exec" command with that value in the -u argument, a similar issue to CVE-2016-3697.

oryginał EN
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Hyper Runv

    APP
    Hyper
    1.0.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Container
CWE
Referencje

Powiązane podatności

CVE-2019-25009CRITICAL9.8PL ✓ten sam vendor

Double-Free w bibliotece http dla Rust — podatność HeaderMap::Drain

CVE-2020-35863CRITICAL9.8PL ✓ten sam vendor

HTTP request smuggling i RCE w bibliotece hyper dla Rust

CVE-2023-26964HIGH7.5ten sam vendor

An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP...

CVE-2022-31394HIGH7.5ten sam vendor

Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 th...

CVE-2020-25574HIGH7.5ten sam vendor

An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() ...