« Volver al listado

CVE-2017-14992

Estado: ModificadaMedia (6.5)—

Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-14992",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-11-01T17:29:00.277",
  "references": [
    {
      "url": "https://blog.cloudpassage.com/2017/10/13/discovering-docker-cve-2017-14992/",
      "tags": [
        "Third Party Advisory",
        "URL Repurposed"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/moby/moby/issues/35075",
      "tags": [
        "Issue Tracking"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://blog.cloudpassage.com/2017/10/13/discovering-docker-cve-2017-14992/",
      "tags": [
        "Third Party Advisory",
        "URL Repurposed"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/moby/moby/issues/35075",
      "tags": [
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing."
    },
    {
      "lang": "es",
      "value": "Una falta de verificación en Docker-CE (también conocido como Moby), en versiones 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0 y anteriores, permite que un atacante remoto provoque una denegación de servicio (DoS) mediante un payload de capa de imagen modificado. Esto también se conoce como gzip bombing."
    }
  ],
  "lastModified": "2026-06-17T01:07:06.710",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:docker:docker:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE591C14-3685-468F-82F6-66D8C8345A44",
              "versionEndIncluding": "1.10.3"
            },
            {
              "criteria": "cpe:2.3:a:docker:docker:1.12.6-0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8C5AD32-AF7A-434D-A60A-E2EF8A696D52"
            },
            {
              "criteria": "cpe:2.3:a:docker:docker:17.03.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57021B99-94F4-40BD-9E2F-BD27904C98A2"
            },
            {
              "criteria": "cpe:2.3:a:docker:docker:17.03.1:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "45128BF6-D780-42F3-8C1C-57D037616A64"
            },
            {
              "criteria": "cpe:2.3:a:docker:docker:17.03.2:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A15C4D3-3DBE-4C6B-89B9-9BDA6B8645FB"
            },
            {
              "criteria": "cpe:2.3:a:docker:docker:17.06.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47671AEE-DE9E-4BC4-99B2-C3356DCEE8B0"
            },
            {
              "criteria": "cpe:2.3:a:docker:docker:17.06.1:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FCFBF621-562E-4CC6-9F56-BB764B9DAD40"
            },
            {
              "criteria": "cpe:2.3:a:docker:docker:17.06.2:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EAA1799F-F848-47BF-99D8-87E0A142DBAB"
            },
            {
              "criteria": "cpe:2.3:a:docker:docker:17.09.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BCA8B266-883A-482E-B756-1F0F8A4BFF46"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}