Vulnerability Description
An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Docker | Docker | < 1.5.0 |
| Apache | Geode | 1.12.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2015/03/24/18Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2015/03/24/22Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2015/03/24/23Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/cve-2014-0048Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0048Issue TrackingThird Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2014-0048Issue TrackingThird Party Advisory
- https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741Issue TrackingMailing List
- https://security-tracker.debian.org/tracker/CVE-2014-0048Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/03/24/18Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2015/03/24/22Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2015/03/24/23Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/cve-2014-0048Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0048Issue TrackingThird Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2014-0048Issue TrackingThird Party Advisory
- https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741Issue TrackingMailing List
FAQ
What is CVE-2014-0048?
CVE-2014-0048 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.
How severe is CVE-2014-0048?
CVE-2014-0048 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2014-0048?
Check the references section above for vendor advisories and patch information. Affected products include: Docker Docker, Apache Geode.