Security update for docker
Announcement ID: | SUSE-SU-2015:1757-1 |
---|---|
Rating: | important |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves two vulnerabilities can now be installed.
Description:
docker was updated to version 1.8.3 to fix two security issues.
These security issues were fixed: - CVE-2014-8178: Manipulated layer IDs could have lead to local graph poisoning (bsc#949660). - CVE-2014-8179: Manifest validation and parsing logic errors allowed pull-by-digest validation bypass (bsc#949660).
This non-security issues was fixed:
- Add --disable-legacy-registry
to prevent a daemon from using a v1 registry
More information about docker 1.8.3 can be found at https://blog.docker.com/2015/10/security-release-docker-1-8-3-1-6-2-cs7/
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
Containers Module 12
zypper in -t patch SUSE-SLE-Module-Containers-12-2015-691=1
Package List:
-
Containers Module 12 (x86_64)
- docker-debugsource-1.8.3-49.1
- docker-1.8.3-49.1
- docker-debuginfo-1.8.3-49.1