Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-9780

Опубликовано: 12 июн. 2017
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location. In the case of the "system helper" component, files deployed as part of the app are owned by root, so in the worst case they could be setuid root.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7flatpakNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-270
https://bugzilla.redhat.com/show_bug.cgi?id=1465025flatpak: Privilege escalation via setuid/world-writable file permissions

EPSS

Процентиль: 29%
0.00355
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 9 лет назад

In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location. In the case of the "system helper" component, files deployed as part of the app are owned by root, so in the worst case they could be setuid root.

CVSS3: 7.8
nvd
около 9 лет назад

In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location. In the case of the "system helper" component, files deployed as part of the app are owned by root, so in the worst case they could be setuid root.

CVSS3: 7.8
debian
около 9 лет назад

In Flatpak before 0.8.7, a third-party app repository could include ma ...

CVSS3: 7.8
github
больше 4 лет назад

In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location. In the case of the "system helper" component, files deployed as part of the app are owned by root, so in the worst case they could be setuid root.

suse-cvrf
больше 8 лет назад

Security update for flatpak

EPSS

Процентиль: 29%
0.00355
Низкий

7 High

CVSS3