Manipulated layer IDs could have lead to local graph poisoning (CVE-2014-8178).
Manifest validation and parsing logic errors allowed pull-by-digest validation bypass (CVE-2014-8179).
To fix these issues, the golang package has been updated to version 1.4.3 and the docker package has been updated to version 1.9.1.