sylvainlasnier / memcached Goto Github PK
View Code? Open in Web Editor NEWMemcached Docker Image
License: GNU General Public License v3.0
Memcached Docker Image
License: GNU General Public License v3.0
Hi,
it seems that this image is vulnerable to the following "shellshock related" bugs.
CVE-2014-6271, CVE-2014-7169, CVE-2014-6277, CVE-2014-6278
I have no idea if they are exploitable given your use case, but you probably want to update the OS just in case.
can't find the user root to switch to
Doing docker stop
on this memcache image leaves it with Exit status -1 (also meaning it stops slowly because there must be a timeout where docker is then failing back to docker kill
).
To reproduce:
$ docker run --name memcached -d -p 11211 sylvainlasnier/memcached
ac1d22f7a6ad9b39bc240a8d2fd3791a032a2fa687f3dcb1a9f47e1e9b8698e5
$ docker ps | head -n 2
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
ac1d22f7a6ad sylvainlasnier/memcached:latest "/bin/sh -c '/usr/bi" 3 seconds ago Up 2 seconds 0.0.0.0:49155->11211/tcp memcached
$ docker stop memcached
$ docker ps -a | head -n 2
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
ac1d22f7a6ad sylvainlasnier/memcached:latest "/bin/sh -c '/usr/bi" 28 seconds ago Exited (-1) 8 seconds ago memcached
See: Exited (-1)
Other people have reported they can exit memcache cleanly. e.g. moby/moby#5137
I also saw there was talk of an offical memcached image - docker-library/official-images#80 - mentions the same exit status problem.
I also spotted another mention of the problem in the fig repo: docker/compose#273
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.