MGASA-2020-0050

Source
https://advisories.mageia.org/MGASA-2020-0050.html
Import Source
https://advisories.mageia.org/MGASA-2020-0050.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0050
Related
Published
2020-01-28T07:52:40Z
Modified
2020-01-28T07:27:06Z
Summary
Updated opencontainers-runc packages fix security vulnerability
Details

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory (CVE-2019-16884).

References
Credits

Affected packages

Mageia:7 / opencontainers-runc

Package

Name
opencontainers-runc
Purl
pkg:rpm/mageia/opencontainers-runc?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.0-0.rc9.3.mga7

Ecosystem specific

{
    "section": "core"
}