{"schema_version":"1.7.3","id":"openSUSE-SU-2019:0189-1","published":"2019-03-23T11:00:22Z","modified":"2026-02-04T04:07:09.585360Z","related":["CVE-2018-16873","CVE-2018-16874","CVE-2018-16875"],"upstream":["CVE-2018-16873","CVE-2018-16874","CVE-2018-16875"],"summary":"Security update for docker","details":"This update for containerd, docker, docker-runc and golang-github-docker-libnetwork fixes the following issues:\n\nSecurity issues fixed for containerd, docker, docker-runc and golang-github-docker-libnetwork:\n\n- CVE-2018-16873: cmd/go: remote command execution during 'go get -u' (bsc#1118897)\n- CVE-2018-16874: cmd/go: directory traversal in 'go get' via curly braces in import paths (bsc#1118898)\n- CVE-2018-16875: crypto/x509: CPU denial of service (bsc#1118899)\n\nNon-security issues fixed for docker:\n\n- Disable leap based builds for kubic flavor (bsc#1121412)\n- Allow users to explicitly specify the NIS domainname of a container (bsc#1001161)\n- Update docker.service to match upstream and avoid rlimit problems (bsc#1112980)\n- Allow docker images larger then 23GB (bsc#1118990)\n- Docker version update to version 18.09.0-ce (bsc#1115464)\n\nThis update was imported from the SUSE:SLE-15:Update update project.","references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWOQPNXXBRMZ3GUIAPIJWBLSX4C6UKIN/#XWOQPNXXBRMZ3GUIAPIJWBLSX4C6UKIN"},{"type":"REPORT","url":"https://bugzilla.suse.com/1001161"},{"type":"REPORT","url":"https://bugzilla.suse.com/1112980"},{"type":"REPORT","url":"https://bugzilla.suse.com/1115464"},{"type":"REPORT","url":"https://bugzilla.suse.com/1118897"},{"type":"REPORT","url":"https://bugzilla.suse.com/1118898"},{"type":"REPORT","url":"https://bugzilla.suse.com/1118899"},{"type":"REPORT","url":"https://bugzilla.suse.com/1118990"},{"type":"REPORT","url":"https://bugzilla.suse.com/1121412"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16873"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16874"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16875"}]}