CVE Database
/

CVE-2019-5736

Back to search

CVE-2019-5736

Published: Feb 11, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2019:0408
vendor-advisory
RHSA-2019:0401
vendor-advisory
RHSA-2019:0303
vendor-advisory
46359
exploit
46369
exploit
RHSA-2019:0304
vendor-advisory
106976
vdb-entry
openSUSE-SU-2019:1079
vendor-advisory
openSUSE-SU-2019:1227
vendor-advisory
openSUSE-SU-2019:1275
vendor-advisory
FEDORA-2019-bc70b381ad
vendor-advisory
FEDORA-2019-6174b47003
vendor-advisory
RHSA-2019:0975
vendor-advisory
openSUSE-SU-2019:1444
vendor-advisory
openSUSE-SU-2019:1481
vendor-advisory
openSUSE-SU-2019:1499
vendor-advisory
openSUSE-SU-2019:1506
vendor-advisory
USN-4048-1
vendor-advisory
openSUSE-SU-2019:2021
vendor-advisory
FEDORA-2019-2baa1f7b19
vendor-advisory
FEDORA-2019-c1dac1b3b8
vendor-advisory
openSUSE-SU-2019:2245
vendor-advisory
openSUSE-SU-2019:2286
vendor-advisory
GLSA-202003-21
vendor-advisory

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now