| Added |
CPE Configuration |
|
OR
*cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:* versions up to (including) 18.09.2 |
| Added |
CPE Configuration |
|
OR
*cpe:2.3:a:google:kubernetes_engine:-:*:*:*:*:*:*:* |
| Added |
CPE Configuration |
|
OR
*cpe:2.3:a:linuxcontainers:lxc:-:*:*:*:*:*:*:* |
| Added |
CPE Configuration |
|
OR
*cpe:2.3:a:opencontainers:runc:*:*:*:*:*:*:*:* versions up to (including) 1.0 |
| Added |
CPE Configuration |
|
OR
*cpe:2.3:a:opencontainers:runc:1.0:rc1:*:*:*:*:*:*
*cpe:2.3:a:opencontainers:runc:1.0:rc2:*:*:*:*:*:*
*cpe:2.3:a:opencontainers:runc:1.0:rc3:*:*:*:*:*:*
*cpe:2.3:a:opencontainers:runc:1.0:rc4:*:*:*:*:*:*
*cpe:2.3:a:opencontainers:runc:1.0:rc5:*:*:*:*:*:*
*cpe:2.3:a:opencontainers:runc:1.0:rc6:*:*:*:*:*:* |
| Added |
CPE Configuration |
|
OR
*cpe:2.3:a:redhat:openshift:3.9:*:*:*:enterprise:*:*:*
*cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
*cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* |
| Added |
CVSS V2 |
|
(AV:N/AC:M/Au:N/C:C/I:C/A:C) |
| Added |
CVSS V2 Metadata |
|
Victim must voluntarily interact with attack mechanism |
| Added |
CVSS V3 |
|
AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
| Added |
CWE |
|
CWE-216 |
| Changed |
Reference Type |
http://www.securityfocus.com/bid/106976 No Types Assigned |
http://www.securityfocus.com/bid/106976 Third Party Advisory |
| Changed |
Reference Type |
https://access.redhat.com/errata/RHSA-2019:0303 No Types Assigned |
https://access.redhat.com/errata/RHSA-2019:0303 Third Party Advisory |
| Changed |
Reference Type |
https://access.redhat.com/errata/RHSA-2019:0304 No Types Assigned |
https://access.redhat.com/errata/RHSA-2019:0304 Third Party Advisory |
| Changed |
Reference Type |
https://access.redhat.com/security/cve/cve-2019-5736 No Types Assigned |
https://access.redhat.com/security/cve/cve-2019-5736 Third Party Advisory |
| Changed |
Reference Type |
https://access.redhat.com/security/vulnerabilities/runcescape No Types Assigned |
https://access.redhat.com/security/vulnerabilities/runcescape Third Party Advisory |
| Changed |
Reference Type |
https://aws.amazon.com/security/security-bulletins/AWS-2019-002/ No Types Assigned |
https://aws.amazon.com/security/security-bulletins/AWS-2019-002/ Third Party Advisory |
| Changed |
Reference Type |
https://brauner.github.io/2019/02/12/privileged-containers.html No Types Assigned |
https://brauner.github.io/2019/02/12/privileged-containers.html Exploit, Technical Description, Third Party Advisory |
| Changed |
Reference Type |
https://cloud.google.com/kubernetes-engine/docs/security-bulletins#february-11-2019-runc No Types Assigned |
https://cloud.google.com/kubernetes-engine/docs/security-bulletins#february-11-2019-runc Third Party Advisory |
| Changed |
Reference Type |
https://github.com/docker/docker-ce/releases/tag/v18.09.2 No Types Assigned |
https://github.com/docker/docker-ce/releases/tag/v18.09.2 Release Notes, Third Party Advisory, Vendor Advisory |
| Changed |
Reference Type |
https://github.com/Frichetten/CVE-2019-5736-PoC No Types Assigned |
https://github.com/Frichetten/CVE-2019-5736-PoC Third Party Advisory |
| Changed |
Reference Type |
https://github.com/opencontainers/runc/commit/0a8e4117e7f715d5fbeef398405813ce8e88558b No Types Assigned |
https://github.com/opencontainers/runc/commit/0a8e4117e7f715d5fbeef398405813ce8e88558b Patch, Third Party Advisory |
| Changed |
Reference Type |
https://github.com/opencontainers/runc/commit/6635b4f0c6af3810594d2770f662f34ddc15b40d No Types Assigned |
https://github.com/opencontainers/runc/commit/6635b4f0c6af3810594d2770f662f34ddc15b40d Patch, Third Party Advisory |
| Changed |
Reference Type |
https://github.com/q3k/cve-2019-5736-poc No Types Assigned |
https://github.com/q3k/cve-2019-5736-poc Third Party Advisory |
| Changed |
Reference Type |
https://github.com/rancher/runc-cve No Types Assigned |
https://github.com/rancher/runc-cve Third Party Advisory |
| Changed |
Reference Type |
https://kubernetes.io/blog/2019/02/11/runc-and-cve-2019-5736/ No Types Assigned |
https://kubernetes.io/blog/2019/02/11/runc-and-cve-2019-5736/ Third Party Advisory |
| Changed |
Reference Type |
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190215-runc No Types Assigned |
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190215-runc Third Party Advisory |
| Changed |
Reference Type |
https://www.exploit-db.com/exploits/46359/ No Types Assigned |
https://www.exploit-db.com/exploits/46359/ Exploit, Third Party Advisory |
| Changed |
Reference Type |
https://www.exploit-db.com/exploits/46369/ No Types Assigned |
https://www.exploit-db.com/exploits/46369/ Exploit, Third Party Advisory |
| Changed |
Reference Type |
https://www.openwall.com/lists/oss-security/2019/02/11/2 No Types Assigned |
https://www.openwall.com/lists/oss-security/2019/02/11/2 Mailing List, Patch, Third Party Advisory |
| Changed |
Reference Type |
https://www.twistlock.com/2019/02/11/how-to-mitigate-cve-2019-5736-in-runc-and-docker/ No Types Assigned |
https://www.twistlock.com/2019/02/11/how-to-mitigate-cve-2019-5736-in-runc-and-docker/ Third Party Advisory |