Fedora 20 Security Update: docker-io-1.4.1-4.fc20

Resolved Bugs
1180059 – SELinux is preventing /usr/bin/docker from ‘getattr’ accesses on the file /.docker/key.json.
1173324 – CVE-2014-9357 CVE-2014-9356 CVE-2014-9358 docker-io: various flaws [fedora-all]
1172782 – CVE-2014-9357 docker: Escalation of privileges during decompression of LZMA archives
1172761 – CVE-2014-9356 docker: Path traversal during processing of absolute symlinks
1172787 – CVE-2014-9358 docker: Path traversal and spoofing opportunities presented through image identifiers<br
allow unitfile to use /etc/sysconfig/docker-network
Security fix for CVE-2014-9357, CVE-2014-9358, CVE-2014-9356

Leave a Reply