Bug#962141: docker.io: CVE-2020-13401

2020-07-02 Thread Moritz Mühlenhoff
On Sun, Jun 14, 2020 at 11:23:41PM +0200, Felix Geyer wrote: > Hi security team / maintainers, > > On Wed, 03 Jun 2020 20:58:53 +0200 Salvatore Bonaccorso > wrote: > > Source: docker.io > > Version: 19.03.7+dfsg1-3 > > Severity: important > > Tags: security upstream > > > > Hi, > > > > The

Bug#962141: docker.io: CVE-2020-13401

2020-06-18 Thread Arnaud Rebillout
On 6/15/20 7:57 AM, Dmitry Smirnov wrote: On Monday, 15 June 2020 7:23:41 AM AEST Felix Geyer wrote: I've prepared an update for buster-security (debdiff attached). With the update accept_ra is correctly set to 0 for bridges Docker creates. Many thanks for your help, Felix. @Maintainers:

Bug#962141: docker.io: CVE-2020-13401

2020-06-15 Thread Moritz Muehlenhoff
On Sun, Jun 14, 2020 at 11:23:41PM +0200, Felix Geyer wrote: > Hi security team / maintainers, > > On Wed, 03 Jun 2020 20:58:53 +0200 Salvatore Bonaccorso > wrote: > > Source: docker.io > > Version: 19.03.7+dfsg1-3 > > Severity: important > > Tags: security upstream > > > > Hi, > > > > The

Bug#962141: docker.io: CVE-2020-13401

2020-06-14 Thread Dmitry Smirnov
On Monday, 15 June 2020 7:23:41 AM AEST Felix Geyer wrote: > I've prepared an update for buster-security (debdiff attached). > With the update accept_ra is correctly set to 0 for bridges Docker creates. Many thanks for your help, Felix. > @Maintainers: > Do you want me push the patch to the Git

Bug#962141: docker.io: CVE-2020-13401

2020-06-14 Thread Felix Geyer
Hi security team / maintainers, On Wed, 03 Jun 2020 20:58:53 +0200 Salvatore Bonaccorso wrote: Source: docker.io Version: 19.03.7+dfsg1-3 Severity: important Tags: security upstream Hi, The following vulnerability was published for docker.io. CVE-2020-13401[0]: | An issue was discovered in

Bug#962141: docker.io: CVE-2020-13401

2020-06-03 Thread Salvatore Bonaccorso
Source: docker.io Version: 19.03.7+dfsg1-3 Severity: important Tags: security upstream Hi, The following vulnerability was published for docker.io. CVE-2020-13401[0]: | An issue was discovered in Docker Engine before 19.03.11. An attacker | in a container, with the CAP_NET_RAW capability, can