{"affected":[{"ecosystem_specific":{"binaries":[{"docker":"1.6.2-31.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12","name":"docker","purl":"pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.6.2-31.2"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"docker":"1.6.2-31.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"docker","purl":"pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.6.2-31.2"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"The Linux container runtime environment Docker was updated to version 1.6.2\nto fix several security and non-security issues.\n\n- Security:\n  - Fix read/write /proc paths. (CVE-2015-3630)\n  - Prohibit VOLUME /proc and VOLUME /. (CVE-2015-3631)\n  - Fix opening of file-descriptor 1. (CVE-2015-3627)\n  - Fix symlink traversal on container respawn allowing local privilege\n    escalation. (CVE-2015-3629)\n\n- Runtime:\n  - Update Apparmor policy to not allow mounts.\n","id":"SUSE-SU-2015:0984-1","modified":"2015-05-19T18:41:00Z","published":"2015-05-19T18:41:00Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20150984-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/930235"},{"type":"REPORT","url":"https://bugzilla.suse.com/931301"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-3627"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-3629"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-3630"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-3631"}],"related":["CVE-2015-3627","CVE-2015-3629","CVE-2015-3630","CVE-2015-3631"],"summary":"Security update for docker","upstream":["CVE-2015-3627","CVE-2015-3629","CVE-2015-3630","CVE-2015-3631"]}