CVE-2014-9358
Publication date 16 December 2014
Last updated 24 July 2024
Ubuntu priority
Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."
Status
Package | Ubuntu Release | Status |
---|---|---|
docker.io | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |