{"id":"CVE-2014-6407","aliases":["GHSA-5qgp-p5jc-w2rm","GO-2022-0630"],"url":"https://o3.security/vulnerability/CVE-2014-6407","summary":"Arbitrary Code Execution in Docker","details":"Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.","published":"2014-12-12T15:59:04Z","modified":"2026-04-10T03:44:00.161690Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":{"score":0.04909,"percentile":0.91421,"asOf":"2026-08-20"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/docker/docker","fixedVersion":"1.3.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/60171"},{"type":"ADVISORY","url":"http://secunia.com/advisories/60241"},{"type":"ADVISORY","url":"https://docs.docker.com/v1.3/release-notes/"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145154.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00009.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/11/24/5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:44:00.161690Z"}}