ELSA-2015-3085

ELSA-2015-3085 - docker-engine security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2015-10-14

Description


[1.8.3-1.0.1]
- Enable configuration of Docker daemon via sysconfig [orabug 21804877]
- Add documentation files to binary RPM

[1.8.3]
- Fix layer IDs lead to local graph poisoning (CVE-2014-8178)
- Fix manifest validation and parsing logic errors allow pull-by-digest validation bypass (CVE-2014-8179)
- Add --disable-legacy-registry to prevent a daemon from using a v1 registry


Related CVEs


CVE-2014-8178
CVE-2014-8179

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 6 (x86_64) docker-engine-1.8.3-1.0.1.el6.src.rpm4dd937eaa900b677b2532f43fc4c7dd9ELSA-2017-3511
docker-engine-1.8.3-1.0.1.el6.x86_64.rpmefd43c055c8f3790730160b1743d8dfaELSA-2017-3511
Oracle Linux 7 (x86_64) docker-engine-1.8.3-1.0.1.el7.src.rpme914b7968a816a48cd288f86f277d197ELBA-2021-9201
docker-engine-1.8.3-1.0.1.el7.x86_64.rpmf640a3d96932f675449ca3a8aa930554ELBA-2021-9201



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete