Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-8308

Опубликовано: 11 фев. 2019
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

A flaw was found in flatpak. In certain special cases, installing flatpak applications and runtimes system-wide may allow an attacker to escape the flatpak sandbox. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

This flaw appears to impact systems in special cases involving installing flatpak applications and runtimes system-wide. Installation of flatpak applications and runtimes locally should not be impacted.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8flatpakNot affected
Red Hat Enterprise Linux 7flatpakFixedRHSA-2019:037519.02.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-672
https://bugzilla.redhat.com/show_bug.cgi?id=1675070flatpak: potential /proc based sandbox escape

EPSS

Процентиль: 21%
0.00068
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 6 лет назад

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

CVSS3: 8.2
nvd
больше 6 лет назад

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

CVSS3: 8.2
debian
больше 6 лет назад

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc ...

CVSS3: 8.2
github
больше 3 лет назад

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

oracle-oval
больше 6 лет назад

ELSA-2019-0375: flatpak security update (IMPORTANT)

EPSS

Процентиль: 21%
0.00068
Низкий

7.7 High

CVSS3