Описание
If a malicious SDK container declares an extension point with a crafted directory path, and a developer runs flatpak build-init --writable-sdk --sdk-extension with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows .. traversal.
Меры по смягчению последствий
Fixed in v1.18.1. Avoid using an non-trusted SDK for development/compilation.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | flatpak | Under investigation | ||
| Red Hat Enterprise Linux 7 | flatpak | Under investigation | ||
| Red Hat Enterprise Linux 8 | flatpak | Under investigation | ||
| Red Hat Enterprise Linux 9 | flatpak | Under investigation |
Показывать по
Дополнительная информация
Статус:
EPSS
Связанные уязвимости
If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal.
If a malicious SDK container declares an extension point with a crafte ...
EPSS