CVE-2019-1020014Double Free in Docker Docker-credential-helpers

CWE-415Double Free9 documents6 sources
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 76.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 29
Latest updateMay 24

Description

docker-credential-helpers before 0.6.3 has a double free in the List functions.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/golang-github-docker-docker-credential-helpers< golang-github-docker-docker-credential-helpers 0.6.1-3 (bookworm)

Also affects: Fedora 32, Ubuntu Linux 16.04, 18.04, 19.04

Patches

🔴Vulnerability Details

2
GHSA
GHSA-h8cp-ph26-xwmv: docker-credential-helpers before 02022-05-24
OSV
CVE-2019-1020014: docker-credential-helpers before 02019-07-29

📋Vendor Advisories

4
Ubuntu
docker-credential-helpers vulnerability2021-03-15
Ubuntu
docker-credential-helpers vulnerability2019-08-19
Ubuntu
Docker vulnerability2019-08-19
Debian
CVE-2019-1020014: golang-github-docker-docker-credential-helpers - docker-credential-helpers before 0.6.3 has a double free in the List functions.2019

💬Community

2
Bugzilla
CVE-2019-1020014 golang-github-docker-credential-helpers: docker-credential-helpers: use-after-free in the List functions [fedora-all]2020-05-07
Bugzilla
CVE-2019-1020014 docker-credential-helpers: double-free in the List functions2020-05-05
CVE-2019-1020014 — Double Free in Docker | cvebase