ELSA-2015-3085

ELSA-2015-3085 - docker-engine security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2015-10-14

Description


[1.8.3-1.0.1]
- Enable configuration of Docker daemon via sysconfig [orabug 21804877]
- Add documentation files to binary RPM

[1.8.3]
- Fix layer IDs lead to local graph poisoning (CVE-2014-8178)
- Fix manifest validation and parsing logic errors allow pull-by-digest validation bypass (CVE-2014-8179)
- Add --disable-legacy-registry to prevent a daemon from using a v1 registry


Related CVEs


CVE-2014-8178
CVE-2014-8179

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 6 (x86_64) docker-engine-1.8.3-1.0.1.el6.src.rpm9ee3e5cf0bb80259f4f839f4594106d15800ffdba73e28eda134383ae6d57db4ELSA-2017-3511ol6_x86_64_addons
docker-engine-1.8.3-1.0.1.el6.x86_64.rpma844b3e543e3b055b36ba65bc95c780e475b95b5b1d31cc7a593481e8d8dbee4ELSA-2017-3511ol6_x86_64_addons
Oracle Linux 7 (x86_64) docker-engine-1.8.3-1.0.1.el7.src.rpm4a93df62e5235e1cc6d8902a0634574c6cd303fa61fd3b743ebff35b916c8b4bELSA-2021-9373ol7_x86_64_addons
docker-engine-1.8.3-1.0.1.el7.x86_64.rpm88100115fde394a32b0e081677480c4d72a103daae451e7db23b758429de6220ELSA-2021-9373ol7_x86_64_addons



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete