Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2019-5736

Quick assessment

Affected
n/a n/a
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Docker是美国Docker公司的一款开源的应用容器引擎。该产品支持在Linux系统上创建一个容器(轻量级虚拟机)并部署和运行应用程序,以及通过配置文件实现应用程序的自动化安装、部署和升级。 Docker 18.09.2之前版本和其他产品中的runc 1.0-rc6及之前版本中存在安全漏洞,该漏洞源于程序没有正确地处理文件描述符。攻击者可利用该漏洞覆盖主机runc的二进制文件并以root权限执行命令。

AI Predicted 9.8 Difficulty: Easy EPSS 98.45% · P100
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2019-5736

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Docker 操作系统命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Docker是美国Docker公司的一款开源的应用容器引擎。该产品支持在Linux系统上创建一个容器(轻量级虚拟机)并部署和运行应用程序,以及通过配置文件实现应用程序的自动化安装、部署和升级。 Docker 18.09.2之前版本和其他产品中的runc 1.0-rc6及之前版本中存在安全漏洞,该漏洞源于程序没有正确地处理文件描述符。攻击者可利用该漏洞覆盖主机runc的二进制文件并以root权限执行命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2019-5736

# POC Description Source Link Shenlong Link
1 Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape) https://github.com/q3k/cve-2019-5736-poc POC Details
2 PoC for CVE-2019-5736 https://github.com/Frichetten/CVE-2019-5736-PoC POC Details
3 runc容器逃逸漏洞预警 https://github.com/jas502n/CVE-2019-5736 POC Details
4 None https://github.com/likescam/CVE-2019-5736 POC Details
5 None https://github.com/likescam/cve-2019-5736-poc POC Details
6 getshell test https://github.com/agppp/cve-2019-5736-poc POC Details
7 None https://github.com/b3d3c/poc-cve-2019-5736 POC Details
8 CVE-2019-5736 POCs https://github.com/twistlock/RunC-CVE-2019-5736 POC Details
9 None https://github.com/yyqs2008/CVE-2019-5736-PoC-2 POC Details
10 https://nvd.nist.gov/vuln/detail/CVE-2019-5736 poc of CVE-2019-5736 https://github.com/zyriuse75/CVE-2019-5736-PoC POC Details
11 None https://github.com/stillan00b/CVE-2019-5736 POC Details
12 Exploit for the CVE-2019-5736 runc vulnerability https://github.com/milloni/cve-2019-5736-exp POC Details
13 Docker runc CVE-2019-5736 exploit Dockerfile. Credits : https://github.com/Frichetten/CVE-2019-5736-PoC.git https://github.com/panzouh/Docker-Runc-Exploit POC Details
14 Proof of concept code for breaking out of docker via runC https://github.com/RyanNgWH/CVE-2019-5736-POC POC Details
15 None https://github.com/Lee-SungYoung/cve-2019-5736-study POC Details
16 None https://github.com/chosam2/cve-2019-5736-poc POC Details
17 Code sample for using exploit CVE-2019-5736 to mine bitcoin with no association to original container or user. https://github.com/epsteina16/Docker-Escape-Miner POC Details
18 None https://github.com/geropl/CVE-2019-5736 POC Details
19 CVE-2019-5736 implemented in a self-written container runtime to understand the exploit. https://github.com/GiverOfGifts/CVE-2019-5736-Custom-Runtime POC Details
20 None https://github.com/Billith/CVE-2019-5736-PoC POC Details
21 None https://github.com/BBRathnayaka/POC-CVE-2019-5736 POC Details
22 CVE-2019-5736 https://github.com/shen54/IT19172088 POC Details
23 None https://github.com/crypticdante/CVE-2019-5736 POC Details
24 Modified version of CVE-2019-5736-PoC by Frichetten https://github.com/fahmifj/Docker-breakout-runc POC Details
25 None https://github.com/Asbatel/CVE-2019-5736_POC POC Details
26 None https://github.com/takumak/cve-2019-5736-reproducer POC Details
27 None https://github.com/si1ent-le/CVE-2019-5736 POC Details
28 None https://github.com/H3xL00m/CVE-2019-5736 POC Details
29 None https://github.com/n3ov4n1sh/CVE-2019-5736 POC Details
30 None https://github.com/c0d3cr4f73r/CVE-2019-5736 POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-5736

登录查看更多情报信息。

Patches & Fixes for CVE-2019-5736 (2)

Vendor Advisories for CVE-2019-5736 (13)

Exploits & Public PoCs for CVE-2019-5736 (4)

Mailing List Discussions for CVE-2019-5736 (31)

Security Blog Posts for CVE-2019-5736 (3)

Other References for CVE-2019-5736 (13)

Same Patch Batch · n/a · 2019-02-11 · 31 CVEs total

CVE-2019-7722 PMD 安全漏洞
CVE-2019-7748 DbNinja 跨站脚本漏洞
CVE-2019-7747 DbNinja 安全漏洞
CVE-2019-7738 C.P.Sub 跨站请求伪造漏洞
CVE-2019-7737 Verydows 跨站请求伪造漏洞
CVE-2019-6489 多款Lexmark产品输入验证错误漏洞
CVE-2018-18569 Dundas BI server 安全漏洞
CVE-2019-7736 D-Link DIR-600M C1 授权问题漏洞
CVE-2019-7733 LIVE555 Media Server 输入验证错误漏洞
CVE-2019-7732 LIVE555 资源管理错误漏洞
CVE-2019-7731 MyWebSQL 代码注入漏洞
CVE-2019-7730 MyWebSQL 跨站请求伪造漏洞
CVE-2018-15588 MailMate 输入验证错误漏洞
CVE-2018-15587 GNOME Evolution 数据伪造问题漏洞
CVE-2018-15586 Enigmail 数据伪造问题漏洞
CVE-2018-20772 Frog CMS 代码注入漏洞
CVE-2019-6975 Django 资源管理错误漏洞
CVE-2018-20587 Bitcoin Core和Bitcoin Knots 访问控制错误漏洞
CVE-2019-7721 nc-cms 安全漏洞
CVE-2019-7720 taocms 代码注入漏洞

Showing top 20 of 31 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2019-5736

No comments yet


Leave a comment