CVE-2019-5736

Modified
Published: 11 Feb 2019, 00:00
Last modified:04 Aug 2024, 20:01

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.3 HIGH
v2.0 (nvd)
EPSS Score
59.18% CRITICAL
59% probability +3.88%
KEV
Not listed
Ransomware
No reports
Public exploits
9 found
Dark Web
Not detected

Timeline

11 Feb 2019, 00:00
Published
Vulnerability first disclosed
04 Aug 2024, 20:01
Last Modified
Vulnerability information updated

Description

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

CVSS Metrics

  • v3.1HIGHScore: 8.6CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • v2.0HIGHScore: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 59.18% Percentile: 98%

Techniques & Countermeasures

  • CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Affected Systems

  • apachemesos

    ≥ 1.4.0, < 1.4.3 | ≥ 1.5.0, < 1.5.3 | ≥ 1.6.0, < 1.6.2 | ≥ 1.7.0, < 1.7.2

  • canonicalubuntu_linux

    16.04 | 18.04 | 18.10 | 19.04

  • d2iqdc\/os

    < 1.10.10 | ≥ 1.10.11, < 1.11.9 | ≥ 1.11.10, < 1.12.1

  • d2iqkubernetes_engine

    < 2.2.0-1.13.3

  • dockerdocker

    < 18.09.2

  • fedoraprojectfedora

    29 | 30

  • googlekubernetes_engine

    na

  • hponesphere

    na

  • linuxcontainerslxc

    < 3.2.0

  • linuxfoundationrunc

    ≤ 0.1.1 | 1.0.0:rc1 | 1.0.0:rc2 | 1.0.0:rc3 | 1.0.0:rc4 | 1.0.0:rc5 | 1.0.0:rc6

  • microfocusservice_management_automation

    2018.02 | 2018.05 | 2018.08 | 2018.11

  • netapphci_management_node

    na

  • netappsolidfire

    na

  • opensusebackports_sle

    15.0 | 15.0:sp1

  • opensuseleap

    15.0 | 15.1 | 42.3

  • redhatcontainer_development_kit

    3.7

  • redhatenterprise_linux

    8.0

  • redhatenterprise_linux_server

    7.0

  • redhatopenshift

    3.4 | 3.5 | 3.6 | 3.7

References (66)