Improper Input Validation Affecting docker.io package, versions <18.06.1-0ubuntu2


Severity

Recommended
low

Based on Ubuntu security rating.

Threat Intelligence

EPSS
0.14% (51st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU2404-DOCKERIO-6725560
  • published29 Apr 2024
  • disclosed1 Nov 2017

Introduced: 1 Nov 2017

CVE-2017-14992  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade Ubuntu:24.04 docker.io to version 18.06.1-0ubuntu2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream docker.io package and not the docker.io package as distributed by Ubuntu. See How to fix? for Ubuntu:24.04 relevant fixed versions and status.

Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing.