CVE-2019-5736
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
Productos afectados
n/a · n/aPoCs públicas encontradas — 34
githubgithub.com/Frichetten/CVE-2019-5736-PoC★ 657githubgithub.com/q3k/cve-2019-5736-poc★ 209githubgithub.com/twistlock/RunC-CVE-2019-5736★ 86githubgithub.com/jas502n/CVE-2019-5736★ 14githubgithub.com/agppp/cve-2019-5736-poc★ 7githubgithub.com/epsteina16/Docker-Escape-Miner★ 3githubgithub.com/panzouh/Docker-Runc-Exploit★ 1githubgithub.com/b3d3c/poc-cve-2019-5736★ 1githubgithub.com/likekabin/CVE-2019-5736★ 1githubgithub.com/GiverOfGifts/CVE-2019-5736-Custom-Runtime★ 1githubgithub.com/milloni/cve-2019-5736-exp★ 1githubgithub.com/Billith/CVE-2019-5736-PoC★ 0githubgithub.com/BBRathnayaka/POC-CVE-2019-5736★ 0githubgithub.com/shen54/IT19172088★ 0githubgithub.com/h3x0v3rl0rd/CVE-2019-5736★ 0githubgithub.com/fahmifj/Docker-breakout-runc★ 0githubgithub.com/si1ent-le/CVE-2019-5736★ 0githubgithub.com/takumak/cve-2019-5736-reproducer★ 0githubgithub.com/sonyavalo/CVE-2019-5736-Dockerattack-and-security-mechanism★ 0githubgithub.com/Perimora/cve_2019-5736-PoC★ 0githubgithub.com/sastraadiwiguna-purpleeliteteaming/Holistic-Deconstruction-of-CVE-2019-5736-★ 0githubgithub.com/likekabin/cve-2019-5736-poc★ 0githubgithub.com/yyqs2008/CVE-2019-5736-PoC-2★ 0githubgithub.com/stillan00b/CVE-2019-5736★ 0githubgithub.com/RyanNgWH/CVE-2019-5736-POC★ 0githubgithub.com/Lee-SungYoung/cve-2019-5736-study★ 0githubgithub.com/h-wookie/cve-2019-5736-poc★ 0githubgithub.com/geropl/CVE-2019-5736★ 0exploitdbwww.exploit-db.com/exploits/46369no verificadocve_referencepacketstormsecurity.com/files/165197/Docker-runc-Command-Execution-Proof-Of-Concept.htmlno verificadocve_referencewww.exploit-db.com/exploits/46359/no verificadocve_referencewww.exploit-db.com/exploits/46369/no verificadoexploitdbwww.exploit-db.com/exploits/46359no verificadocve_referencepacketstormsecurity.com/files/163339/Docker-Container-Escape.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00074.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00091.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00060.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00073.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00029.htmlhttp://packetstormsecurity.com/files/163339/Docker-Container-Escape.htmlhttp://packetstormsecurity.com/files/165197/Docker-runc-Command-Execution-Proof-Of-Concept.html