HIGH🇵🇱 Wersja polska

CVE-2018-9862

CVSS 7.8v3.0pub. 2018-04-09upd. 2024-11-21

util.c in runV 1.0.0 for Docker mishandles a numeric username, which allows attackers to obtain root access by leveraging the presence of an initial numeric value on an /etc/passwd line, and then issuing a "docker exec" command with that value in the -u argument, a similar issue to CVE-2016-3697.

CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Hyper Runv

    APP
    Hyper
    1.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2019-25009CRITICAL9.8PL ✓same vendor

Double-Free w bibliotece http dla Rust — podatność HeaderMap::Drain

CVE-2020-35863CRITICAL9.8PL ✓same vendor

HTTP request smuggling i RCE w bibliotece hyper dla Rust

CVE-2023-26964HIGH7.5same vendor

An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP...

CVE-2022-31394HIGH7.5same vendor

Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 th...

CVE-2020-25574HIGH7.5same vendor

An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() ...