Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2014-12-12T15:00:00
Updated: 2024-08-06T12:17:23.673Z
Reserved: 2014-09-15T00:00:00
Link: CVE-2014-6407

No data.

Status : Deferred
Published: 2014-12-12T15:59:04.337
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-6407
