CVE-2019-1020014
published 2019-07-29CVE-2019-1020014: docker-credential-helpers before 0.6.3 has a double free in the List functions.
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.41%
32.8th percentile
docker-credential-helpers before 0.6.3 has a double free in the List functions.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | golang-github-docker-docker-credential-helpers | < golang-github-docker-docker-credential-helpers 0.6.1-3 (bookworm) | golang-github-docker-docker-credential-helpers 0.6.1-3 (bookworm) |
| docker | credential_helpers | < 0.6.3 | 0.6.3 |
| docker | docker-credential-helpers | < 0.6.3 | 0.6.3 |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
docker-credential-helpers vulnerability
vendor_ubuntu·2021-03-15
CVE-2019-1020014 docker-credential-helpers vulnerability
Title: docker-credential-helpers vulnerability
Summary: docker-credential-helpers could be made to crash if it received specially crafted
input.
Jasiel Spelman discovered that docker-credential-helpers has a double free. A
local attacker could use this to cause a denial of service (crash) or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
docker-credential-helpers vulnerability
vendor_ubuntu·2019-08-19
CVE-2019-1020014 docker-credential-helpers vulnerability
Title: docker-credential-helpers vulnerability
Summary: docker-credential-helpers could be made to crash or run programs as your login
Jasiel Spelman discovered that a double free existed in docker-credential-
helpers. A local attacker could use this to cause a denial of service
(crash) or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Docker vulnerability
vendor_ubuntu·2019-08-19
CVE-2019-1020014 Docker vulnerability
Title: Docker vulnerability
Summary: Docker could be made to crash or run programs as your login.
Jasiel Spelman discovered that a double free existed in the docker-credential-
helpers dependency of Docker. A local attacker could use this to cause a denial of service
(crash) or possibly execute arbitrary code.
Original advisory details:
Jasiel Spelman discovered that a double free existed in docker-credential-
helpers. A local attacker could use this to cause a denial of service
(crash) or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-1020014: golang-github-docker-docker-credential-helpers - docker-credential-helpers before 0.6.3 has a double free in the List functions.
vendor_debian·2019·CVSS 5.5
CVE-2019-1020014 [MEDIUM] CVE-2019-1020014: golang-github-docker-docker-credential-helpers - docker-credential-helpers before 0.6.3 has a double free in the List functions.
docker-credential-helpers before 0.6.3 has a double free in the List functions.
Scope: local
bookworm: resolved (fixed in 0.6.1-3)
bullseye: resolved (fixed in 0.6.1-3)
forky: resolved (fixed in 0.6.1-3)
sid: resolved (fixed in 0.6.1-3)
trixie: resolved (fixed in 0.6.1-3)
GHSA
GHSA-h8cp-ph26-xwmv: docker-credential-helpers before 0
ghsa_unreviewed·2022-05-24
CVE-2019-1020014 [MEDIUM] CWE-415 GHSA-h8cp-ph26-xwmv: docker-credential-helpers before 0
docker-credential-helpers before 0.6.3 has a double free in the List functions.
OSV
CVE-2019-1020014: docker-credential-helpers before 0
osv·2019-07-29·CVSS 5.5
CVE-2019-1020014 [MEDIUM] CVE-2019-1020014: docker-credential-helpers before 0
docker-credential-helpers before 0.6.3 has a double free in the List functions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-1020014 golang-github-docker-credential-helpers: docker-credential-helpers: use-after-free in the List functions [fedora-all]
bugzilla·2020-05-07·CVSS 5.5
CVE-2019-1020014 [MEDIUM] CVE-2019-1020014 golang-github-docker-credential-helpers: docker-credential-helpers: use-after-free in the List functions [fedora-all]
CVE-2019-1020014 golang-github-docker-credential-helpers: docker-credential-helpers: use-after-free in the List functions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2019-1020014 docker-credential-helpers: double-free in the List functions
bugzilla·2020-05-05·CVSS 5.5
CVE-2019-1020014 [MEDIUM] CVE-2019-1020014 docker-credential-helpers: double-free in the List functions
CVE-2019-1020014 docker-credential-helpers: double-free in the List functions
A vulnerability was found in docker-credential-helpers before 0.6.3 has a double free in the List functions.
Reference:
https://github.com/docker/docker-credential-helpers/commit/87c80bfba583eadc087810d17aa631ef4e405efc
Discussion:
Created golang-github-docker-credential-helpers tracking bugs for this issue:
Affects: fedora-all [bug 1832922]
https://github.com/docker/docker-credential-helpers/commit/1c9f7ede70a5ab9851f4c9cb37d317fd89cd318ahttps://github.com/docker/docker-credential-helpers/releases/tag/v0.6.3https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6VVFB6UWUK2GQQN7DVUU6GRRAL637A73/https://usn.ubuntu.com/4103-1/https://usn.ubuntu.com/4103-2/https://github.com/docker/docker-credential-helpers/commit/1c9f7ede70a5ab9851f4c9cb37d317fd89cd318ahttps://github.com/docker/docker-credential-helpers/releases/tag/v0.6.3https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6VVFB6UWUK2GQQN7DVUU6GRRAL637A73/https://usn.ubuntu.com/4103-1/https://usn.ubuntu.com/4103-2/
2019-07-29
Published