Docker×ÊÔ´ÖÎÀíÃýÎó·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2019-12-24·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-17150£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8£¬£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Docker < 0.6.3
·ì϶¸ÅÊö
DockerÊÇÃÀ¹úDocker¹«Ë¾µÄÒ»¿î¿ªÔ´µÄÀûÓÃÈÝÆ÷ÒýÇæ¡£¡£¡£¡£¡£¡£¡£¸Ã²úÆ·Ö§³ÖÔÚLinuxϵͳÉÏ´´½¨Ò»¸öÈÝÆ÷£¨ÇáÁ¿¼¶Ðé¹¹»ú£©²¢²¿ÊðºÍÔËÐÐÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Í¨¹ýÅäÖÃÎļþʵÏÖÀûÓ÷¨Ê½µÄ×Ô¶¯°ç×°Öᢲ¿ÊðºÍÉý¼¶¡£¡£¡£¡£¡£¡£¡£
DockerÖеÄdocker-credential-secretservice´æÔÚ×ÊÔ´ÖÎÀíÃýÎó·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚ·¨Ê½ÔÚ¶Ô¶ÔÏó½øÐпªÊͲÙ×÷֮ǰ£¬£¬£¬£¬£¬£¬£¬£¬Ã»Óв鳸öÔÏóÊÇ·ñ´æÔÚ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÌáÉýȨÏÞ²¢Ö´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º
https://www.docker.com/¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.zerodayinitiative.com/advisories/ZDI-19-1030/


¾©¹«Íø°²±¸11010802024551ºÅ