CVE-2019-1020014
CVE-2019-1020014
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
29 Jul 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
docker-credential-helpers before 0.6.3 has a double free in the List functions.
Affected products
Docker · docker-credential-helpersWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://github.com/docker/docker-credential-helpers/commit/1c9f7ede70a5ab9851f4c9cb37d317fd89cd318ahttps://github.com/docker/docker-credential-helpers/releases/tag/v0.6.3https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6VVFB6UWUK2GQQN7DVUU6GRRAL637A73/https://usn.ubuntu.com/4103-1/https://usn.ubuntu.com/4103-2/