CVE-2016-3697

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
01/06/2016
Last modified:
12/04/2025

Description

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:* 1.11.1 (including)
cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:* 0.0.9 (including)
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*