ELSA-2014-3110

ELSA-2014-3110 - docker security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2014-12-30

Description


[1.3.3-1.0.1]
- Rename requirement of docker-io-pkg-devel in %package devel as docker-pkg-devel
- Restore SysV init scripts for Oracle Linux 6
- Require Oracle Unbreakable Enterprise Kernel Release 3 or higher
- Rename as docker.
- Re-enable btrfs graphdriver support

[1.3.3-1]
- Update source to 1.3.3 from https://github.com/docker/docker/releases/tag/v1.3.3
Path traversal during processing of absolute symlinks (CVE-2014-9356)
Escalation of privileges during decompression of LZMA (.xz) archives (CVE-2014-9357)


Related CVEs


CVE-2014-9358
CVE-2014-9357
CVE-2014-9356

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 6 (x86_64) docker-1.3.3-1.0.1.el6.src.rpm680c6be0638463a72708c50f93ea41de91101bd1f66edbc1881399f82779b74aELSA-2015-3037ol6_x86_64_addons
docker-1.3.3-1.0.1.el6.x86_64.rpm21972285b014555a0986ab179b4cb7717702f6d44ef6a3b5935c4ca394304c08ELSA-2015-3037ol6_x86_64_addons
docker-devel-1.3.3-1.0.1.el6.x86_64.rpmf86398c6343a717419c2f19a7776a48cdc52e89a3b84515630c1ab5b4d46af2dELSA-2015-3037ol6_x86_64_addons
docker-pkg-devel-1.3.3-1.0.1.el6.x86_64.rpm71f646b32ac8c01549f45a636d621977e23a8aa2be6cdbef2e0b20cb60cd7c45ELSA-2015-3037ol6_x86_64_addons
Oracle Linux 7 (x86_64) docker-1.3.3-1.0.1.el7.src.rpmc1f81329dd7331a0146c50e42968bd6ab3ee94aa7add326788dd6f239e5d3534ELSA-2015-3037ol7_x86_64_addons
docker-1.3.3-1.0.1.el7.x86_64.rpm94f5e3b96f88afa436ea3a868f12d32e02e68c3c382af200e070e5366f13d1ffELSA-2015-3037ol7_x86_64_addons
docker-devel-1.3.3-1.0.1.el7.x86_64.rpmc63ead1d776c5aff1511f3a06763af5d1a71fd9221fa261863a374b945c9a689ELSA-2015-3037ol7_x86_64_addons
docker-pkg-devel-1.3.3-1.0.1.el7.x86_64.rpmc384655fe6a4352f9b7e360f0d700a9f3102ebf6c64864e9268c4c6b28958532ELSA-2015-3037ol7_x86_64_addons



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete