Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2018-2766

Опубликовано: 25 сент. 2018
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2018-2766: flatpak security update (MODERATE)

[0.8.8-4]

  • Add patch for CVE-2018-6560 (#1547376)

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

flatpak

0.8.8-4.el7_5

flatpak-builder

0.8.8-4.el7_5

flatpak-devel

0.8.8-4.el7_5

flatpak-libs

0.8.8-4.el7_5

Oracle Linux x86_64

flatpak

0.8.8-4.el7_5

flatpak-builder

0.8.8-4.el7_5

flatpak-devel

0.8.8-4.el7_5

flatpak-libs

0.8.8-4.el7_5

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 8 лет назад

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.

CVSS3: 6.5
redhat
почти 8 лет назад

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.

CVSS3: 8.8
nvd
почти 8 лет назад

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.

CVSS3: 8.8
debian
почти 8 лет назад

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0 ...

CVSS3: 8.8
github
больше 3 лет назад

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.