Fedora 21 Security Update: docker-io-1.4.0-1.fc21

Resolved Bugs
1173324 – CVE-2014-9357 CVE-2014-9356 CVE-2014-9358 docker-io: various flaws [fedora-all]
1172761 – CVE-2014-9356 docker: Path traversal during processing of absolute symlinks
1172782 – CVE-2014-9357 docker: Escalation of privileges during decompression of LZMA archives
1172787 – CVE-2014-9358 docker: Path traversal and spoofing opportunities presented through image identifiers
1169151 – docker run fails with ‘finalize namespace setup user setgid operation not supported'<br
Security fix for CVE-2014-9357, CVE-2014-9358, CVE-2014-9356
Revert to using upstream v1.3.2 release
Resolves: rhbz#1169035, rhbz#1169151

Leave a Reply