CVE-2017-11468
published 2017-07-20CVE-2017-11468: Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.19%
86.6th percentile
Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | docker-registry | < docker-registry 2.6.2~ds1-1 (bookworm) | docker-registry 2.6.2~ds1-1 (bookworm) |
| docker | docker_registry | <= 2.6.1 | — |
| github.com | docker_distribution | >= 0 < 2.7.0-rc.0 | 2.7.0-rc.0 |
| github.com | docker_distribution | >= 0 < 2.7.0-rc.0+incompatible | 2.7.0-rc.0+incompatible |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Docker Registry vulnerabilities
vendor_ubuntu·2023-09-04·CVSS 7.5
CVE-2023-2253 [HIGH] Docker Registry vulnerabilities
Title: Docker Registry vulnerabilities
Summary: docker-registry could be made to crash if it received specially crafted
input.
It was discovered that Docker Registry incorrectly handled certain crafted
input, which allowed remote attackers to cause a denial of service. This
issue only affected Ubuntu 16.04 LTS. (CVE-2017-11468)
It was discovered that Docker Registry incorrectly handled certain crafted
input. An attacker could possibly use this issue to cause a denial of
service. (CVE-2017-11468)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
docker-distribution: Does not properly restrict the amount of content accepted from a user
vendor_redhat·2017-07-07·CVSS 7.5
CVE-2017-11468 [HIGH] CWE-770 docker-distribution: Does not properly restrict the amount of content accepted from a user
docker-distribution: Does not properly restrict the amount of content accepted from a user
Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.
It was found that docker-distribution did not properly restrict memory allocation size for a registry instance through the manifest endpoint. An attacker could send a specially crafted request that would exhaust the memory of the docker-distribution service.
Package: kubernetes (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2017-11468: docker-registry - Docker Registry before 2.6.2 in Docker Distribution does not properly restrict t...
vendor_debian·2017·CVSS 7.5
CVE-2017-11468 [HIGH] CVE-2017-11468: docker-registry - Docker Registry before 2.6.2 in Docker Distribution does not properly restrict t...
Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.
Scope: local
bookworm: resolved (fixed in 2.6.2~ds1-1)
bullseye: resolved (fixed in 2.6.2~ds1-1)
forky: resolved (fixed in 2.6.2~ds1-1)
sid: resolved (fixed in 2.6.2~ds1-1)
trixie: resolved (fixed in 2.6.2~ds1-1)
OSV
docker-registry vulnerabilities
osv·2023-09-05·CVSS 7.5
CVE-2017-11468 [HIGH] docker-registry vulnerabilities
docker-registry vulnerabilities
It was discovered that Docker Registry incorrectly handled certain crafted
input, A remote attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-11468)
It was discovered that Docker Registry incorrectly handled certain crafted
input. An attacker could possibly use this issue to cause a denial of
service. (CVE-2023-2253)
OSV
Docker Registry has Allocation of Resources Without Limits or Throttling
osv·2022-05-13
CVE-2017-11468 [HIGH] Docker Registry has Allocation of Resources Without Limits or Throttling
Docker Registry has Allocation of Resources Without Limits or Throttling
Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.
### Specific Go Packages Affected
github.com/docker/distribution/registry/storage
github.com/docker/distribution/registry/handlers
GHSA
Docker Registry has Allocation of Resources Without Limits or Throttling
ghsa·2022-05-13
CVE-2017-11468 [HIGH] CWE-770 Docker Registry has Allocation of Resources Without Limits or Throttling
Docker Registry has Allocation of Resources Without Limits or Throttling
Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.
### Specific Go Packages Affected
github.com/docker/distribution/registry/storage
github.com/docker/distribution/registry/handlers
OSV
Uncontrolled resource allocation in github.com/docker/distribution
osv·2021-04-14
CVE-2017-11468 Uncontrolled resource allocation in github.com/docker/distribution
Uncontrolled resource allocation in github.com/docker/distribution
Various storage methods do not impose limits on how much content is accepted from user requests, allowing a malicious user to force the caller to allocate an arbitrary amount of memory.
OSV
CVE-2017-11468: Docker Registry before 2
osv·2017-07-20·CVSS 7.5
CVE-2017-11468 [HIGH] CVE-2017-11468: Docker Registry before 2
Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-11468 docker-distribution: Does not properly restrict the amount of content accepted from a user [fedora-all]
bugzilla·2017-07-25·CVSS 7.5
CVE-2017-11468 [HIGH] CVE-2017-11468 docker-distribution: Does not properly restrict the amount of content accepted from a user [fedora-all]
CVE-2017-11468 docker-distribution: Does not properly restrict the amount of content accepted from a user [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2017-11468 docker-distribution: Does not properly restrict the amount of content accepted from a user
bugzilla·2017-07-25·CVSS 7.5
CVE-2017-11468 [HIGH] CVE-2017-11468 docker-distribution: Does not properly restrict the amount of content accepted from a user
CVE-2017-11468 docker-distribution: Does not properly restrict the amount of content accepted from a user
Docker Registry in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.
Upstream patch:
https://github.com/docker/distribution/commit/29fa466debaabb64f8559116bbffd20a289d523c
References:
https://github.com/docker/distribution/releases/tag/v2.6.2
Discussion:
Created docker-distribution tracking bugs for this issue:
Affects: fedora-all [bug 1474894]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extras
Via RHSA-2017:2603 https://access.redhat.com/errata/RHSA-2017:2603
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00047.htmlhttps://access.redhat.com/errata/RHSA-2017:2603https://github.com/docker/distribution/pull/2340https://github.com/docker/distribution/releases/tag/v2.6.2http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00047.htmlhttps://access.redhat.com/errata/RHSA-2017:2603https://github.com/docker/distribution/pull/2340https://github.com/docker/distribution/releases/tag/v2.6.2
2017-07-20
Published