Vulnerability Description
Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Docker | Docker | <= 1.10.3 |
Related Weaknesses (CWE)
References
- https://blog.cloudpassage.com/2017/10/13/discovering-docker-cve-2017-14992/Third Party AdvisoryURL Repurposed
- https://github.com/moby/moby/issues/35075Issue Tracking
- https://blog.cloudpassage.com/2017/10/13/discovering-docker-cve-2017-14992/Third Party AdvisoryURL Repurposed
- https://github.com/moby/moby/issues/35075Issue Tracking
FAQ
What is CVE-2017-14992?
CVE-2017-14992 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a...
How severe is CVE-2017-14992?
CVE-2017-14992 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14992?
Check the references section above for vendor advisories and patch information. Affected products include: Docker Docker.