Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-28101

Опубликовано: 16 мар. 2023
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4, if an attacker publishes a Flatpak app with elevated permissions, they can hide those permissions from users of the flatpak(1) command-line interface by setting other permissions to crafted values that contain non-printable control characters such as ESC. A fix is available in versions 1.10.8, 1.12.8, 1.14.4, and 1.15.4. As a workaround, use a GUI like GNOME Software rather than the command-line interface, or only install apps whose maintainers you trust.

A flaw was found in Flatpak, a system for building, distributing, and running sandboxed desktop applications on Linux. Suppose an attacker publishes a Flatpak app with elevated permissions. In that case, they can hide those permissions from users of the flatpak(1) command-line interface by setting other permissions to crafted values that contain non-printable control characters such as ESC.

Меры по смягчению последствий

Use a GUI like GNOME Software rather than the command-line interface, or only install apps whose maintainers you trust.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7flatpakOut of support scope
Red Hat Enterprise Linux 8flatpakFixedRHSA-2023:703814.11.2023
Red Hat Enterprise Linux 9flatpakFixedRHSA-2023:651807.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-116
https://bugzilla.redhat.com/show_bug.cgi?id=2179219flatpak: Metadata with ANSI control codes can cause misleading terminal output

EPSS

Процентиль: 44%
0.00213
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
больше 2 лет назад

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4, if an attacker publishes a Flatpak app with elevated permissions, they can hide those permissions from users of the `flatpak(1)` command-line interface by setting other permissions to crafted values that contain non-printable control characters such as `ESC`. A fix is available in versions 1.10.8, 1.12.8, 1.14.4, and 1.15.4. As a workaround, use a GUI like GNOME Software rather than the command-line interface, or only install apps whose maintainers you trust.

CVSS3: 5
nvd
больше 2 лет назад

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4, if an attacker publishes a Flatpak app with elevated permissions, they can hide those permissions from users of the `flatpak(1)` command-line interface by setting other permissions to crafted values that contain non-printable control characters such as `ESC`. A fix is available in versions 1.10.8, 1.12.8, 1.14.4, and 1.15.4. As a workaround, use a GUI like GNOME Software rather than the command-line interface, or only install apps whose maintainers you trust.

CVSS3: 5
debian
больше 2 лет назад

Flatpak is a system for building, distributing, and running sandboxed ...

CVSS3: 4.3
fstec
больше 2 лет назад

Уязвимость компонента App инструмента для управления приложениями и средами Flatpak, позволяющая нарушителю оказать воздействие на целостность данных

suse-cvrf
около 2 лет назад

Security update for flatpak

EPSS

Процентиль: 44%
0.00213
Низкий

6.2 Medium

CVSS3