Vulnerability CVE-2020-13401: Information

Description

An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.

Severity: MEDIUM (6.0) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L

Published: June 2, 2020
Modified: Nov. 7, 2023
Error type identifier: CWE-20

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
docker-cep919.03.13-alt119.03.13-alt2ALT-PU-2020-2987-1259082Fixed
libnetworkp919.03.13-alt1.git026aaba19.03.13-alt1.git026aabaALT-PU-2020-2986-1259082Fixed
libnetworkc9f219.03.13-alt1.git026aaba20.10.8-alt1.git64b7a45ALT-PU-2020-3028-1259520Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:docker:engine:*:*:*:*:*:*:*:*
      End excliding
      19.03.11

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:a:broadcom:sannav:-:*:*:*:*:*:*:*