Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5xcx-r88v-8v7g

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.

EPSS

Процентиль: 34%
0.00412
Низкий

8.8 High

CVSS3

Дефекты

CWE-436

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.

CVSS3: 6.5
redhat
больше 8 лет назад

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.

CVSS3: 8.8
nvd
больше 8 лет назад

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.

CVSS3: 8.8
debian
больше 8 лет назад

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0 ...

oracle-oval
почти 8 лет назад

ELSA-2018-2766: flatpak security update (MODERATE)

EPSS

Процентиль: 34%
0.00412
Низкий

8.8 High

CVSS3

Дефекты

CWE-436