MGASA-2016-0043

Source
https://advisories.mageia.org/MGASA-2016-0043.html
Import Source
https://advisories.mageia.org/MGASA-2016-0043.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2016-0043
Related
Published
2016-02-05T17:26:09Z
Modified
2016-02-05T17:14:44Z
Summary
Updated docker/golang packages fix security vulnerability
Details

Manipulated layer IDs could have lead to local graph poisoning (CVE-2014-8178).

Manifest validation and parsing logic errors allowed pull-by-digest validation bypass (CVE-2014-8179).

To fix these issues, the golang package has been updated to version 1.4.3 and the docker package has been updated to version 1.9.1.

References
Credits

Affected packages