FS#41440 - [docker] docker.sock permissions set 666
Attached to Project:
Community Packages
Opened by Josh Gates (jgates) - Saturday, 02 August 2014, 00:08 GMT
Last edited by Sébastien Luttringer (seblu) - Saturday, 23 August 2014, 22:56 GMT
Opened by Josh Gates (jgates) - Saturday, 02 August 2014, 00:08 GMT
Last edited by Sébastien Luttringer (seblu) - Saturday, 23 August 2014, 22:56 GMT
|
Details
Description:
The docker sock file /var/run/docker.sock is chmod 666. This should likely be set to 660. The docker sock file /var/run/docker.sock is owned root:root This should likely be owned by root:docker Additional info: * docker 1.1.2-2 Steps to reproduce: Install docker. |
This task depends upon
Closed by Sébastien Luttringer (seblu)
Saturday, 23 August 2014, 22:56 GMT
Reason for closing: Fixed
Additional comments about closing: docker-1:1.2.0-1
Saturday, 23 August 2014, 22:56 GMT
Reason for closing: Fixed
Additional comments about closing: docker-1:1.2.0-1
Comment by
Sébastien Luttringer (seblu) -
Monday, 04 August 2014, 21:58 GMT
This is already fixed upstream:
https://github.com/docker/docker/blob/master/contrib/init/systemd/docker.socket
Comment by
Jason Plum (WarheadsSE) - Friday,
22 August 2014, 12:03 GMT
I wouldn't call this "Very Low" severity, since that socket being
world writable makes a daemon (and containers spawned) accessible
and controllable by any user.