Back to Database
Status published
High
CVE-2014-6407
Docker before 1.3.2 allows remote attackers to write to arbitrary...
Vulnerability Description
Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-6407
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/60241
- http://secunia.com/advisories/60171
- https://docs.docker.com/v1.3/release-notes/
- http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00009.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145154.html
- http://www.openwall.com/lists/oss-security/2014/11/24/5
More from docker
View All →CVE-2025-64443
DNS Rebinding vulnerability present when running MCP Gateway in sse or streaming mode
High
7.3
CVE-2025-62725
Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations
High
8.9
CVE-2025-0495
Secrets leakage to telemetry endpoint via cache backend configuration via buildx
Medium
4.1
CVE-2022-38730
Docker Desktop for Windows before 4.6 allows attackers to overwrite...
Unknown
0
CVE-2022-37326
Docker Desktop for Windows before 4.6.0 allows attackers to delete...
Unknown
0
Affected Vendor
docker
View all reports →Affected Software
docker
Vulnerable Versions:
0, 1.0.0, 1.3.0
Timeline
Official Publish:
December 12th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.