CVE-2019-5736

Aliases:DEBIAN-CVE-2019-5736ALPINE-CVE-2019-5736CGA-2wwv-p7x3-r95fCGA-77qf-qpfm-657jCGA-8cpg-v3jc-vc4mCGA-94x2-9jmf-98fcCGA-978p-7c3v-mv3wCGA-9hwc-8pcw-x5jhCGA-p55f-2wwv-f4wvCGA-pw2g-jxp6-gr33CGA-qcwp-j344-7rx5CGA-rm8q-vfmf-fv6x
Modified
Published: 11 Feb 2019, 00:00
Last modified:04 Aug 2024, 20:01

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.3 HIGH
v2.0 (nvd)
EPSS Score
98.45% CRITICAL
98% probability +43.16%
KEV
Not listed
Ransomware
No reports
Public exploits
9 found
Dark Web
Not detected

Timeline

11 Feb 2019, 00:00
Published
Vulnerability first disclosed
04 Aug 2024, 20:01
Last Modified
Vulnerability information updated

Description

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

CVSS Metrics

  • v3.1HIGHScore: 8.6CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • v2.0HIGHScore: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 98.45% Percentile: 100%

Techniques & Countermeasures

  • CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Affected Systems

  • apachemesos

    ≥ 1.4.0, < 1.4.3 | ≥ 1.5.0, < 1.5.3 | ≥ 1.6.0, < 1.6.2 | ≥ 1.7.0, < 1.7.2

  • alpinelxc

    < 3.1.0-r1 | < 3.1.0-r1 | < 3.1.0-r1 | < 3.1.0-r1 | < 3.1.0-r1 | < 3.1.0-r1 | < 3.1.0-r1 | < 3.1.0-r1 | < 3.1.0-r1 | < 3.1.0-r1 | < 3.1.0-r1 | < 3.1.0-r1 | < 3.1.0-r1 | < 3.1.0-r1 | < 3.1.0-r1 | < 3.1.0-r1

  • chainguardpy3-docker

    < 0

  • chainguardpy3.10-docker

    < 0

  • chainguardpy3.11-docker

    < 0

  • chainguardpy3.12-docker

    < 0

  • chainguardpy3.13-docker

    < 0

  • wolfipy3-docker

    < 0

  • wolfipy3.10-docker

    < 0

  • wolfipy3.11-docker

    < 0

  • wolfipy3.12-docker

    < 0

  • wolfipy3.13-docker

    < 0

  • canonicalubuntu_linux

    16.04 | 18.04 | 18.10 | 19.04

  • d2iqdc\/os

    < 1.10.10 | ≥ 1.10.11, < 1.11.9 | ≥ 1.11.10, < 1.12.1

  • d2iqkubernetes_engine

    < 2.2.0-1.13.3

  • debianlxc

    < 1:3.1.0+really3.0.3-4 | < 1:3.1.0+really3.0.3-4 | < 1:3.1.0+really3.0.3-4 | < 1:3.1.0+really3.0.3-4

  • debianrunc

    < 1.0.0~rc6+dfsg1-2 | < 1.0.0~rc6+dfsg1-2 | < 1.0.0~rc6+dfsg1-2 | < 1.0.0~rc6+dfsg1-2

  • dockerdocker

    < 18.09.2

  • fedoraprojectfedora

    29 | 30

  • googlekubernetes_engine

    na

  • hponesphere

    na

  • linuxcontainerslxc

    < 3.2.0

  • linuxfoundationrunc

    ≤ 0.1.1 | 1.0.0:rc1 | 1.0.0:rc2 | 1.0.0:rc3 | 1.0.0:rc4 | 1.0.0:rc5 | 1.0.0:rc6

  • microfocusservice_management_automation

    2018.02 | 2018.05 | 2018.08 | 2018.11

  • netapphci_management_node

    na

  • netappsolidfire

    na

  • opensusebackports_sle

    15.0 | 15.0:sp1

  • opensuseleap

    15.0 | 15.1 | 42.3

  • redhatcontainer_development_kit

    3.7

  • redhatenterprise_linux

    8.0

  • redhatenterprise_linux_server

    7.0

  • redhatopenshift

    3.4 | 3.5 | 3.6 | 3.7

References (68)