CVE-2014-9357 is a critical vulnerability in Docker 1.3.2 that allows remote attackers to execute arbitrary code with root privileges. This is achieved by exploiting a flaw in the chroot mechanism during the extraction of crafted Docker images or Dockerfile builds contained within LZMA archives. With a CVSS score of 10.0, it represents a severe risk due to its network-based attack vector, low attack complexity, and complete impact on confidentiality, integrity, and availability. While there is no public exploit code available in common databases and it is not listed in CISA's KEV, the vulnerability has received significant community discussion and media coverage, indicating its importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.2CPE matchmatch criteria | cpe:2.3:a:docker:docker:1.3.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.