Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 24

Количество 24

fstec логотип

BDU:2024-03113

больше 2 лет назад

Уязвимость интерфейса xdg-desktop-portal инструмента для управления приложениями и средами Flatpak, позволяющая нарушителю выйти из изолированной программной среды и получить доступ к файлам в базовой системе

CVSS3: 8.4
EPSS: Низкий
redos логотип

ROS-20240507-06

больше 2 лет назад

Уязвимость flatpak

CVSS3: 8.4
EPSS: Низкий
altlinux логотип

ALT-PU-2024-6956

больше 2 лет назад

ALT-PU-2024-6956: package `flatpak` update to version 1.14.6-alt1

CVSS3: 8.4
EPSS: Низкий
altlinux логотип

ALT-PU-2024-6954

больше 2 лет назад

ALT-PU-2024-6954: package `flatpak` update to version 1.14.6-alt1

CVSS3: 8.4
EPSS: Низкий
altlinux логотип

ALT-PU-2024-6822

больше 2 лет назад

ALT-PU-2024-6822: package `xdg-desktop-portal` update to version 1.18.4-alt1

CVSS3: 8.4
EPSS: Низкий
ubuntu логотип

CVE-2024-32462

больше 2 лет назад

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. Normally, the `--command` argument of `flatpak run` expects to be given a command to run in the specified Flatpak app, optionally along with some arguments. However it is possible to instead pass `bwrap` arguments to `--command=`, such as `--bind`. It's possible to pass an arbitrary `commandline` to the portal interface `org.freedesktop.portal.Background.RequestBackground` from within a Flatpak app. When this is converted into a `--command` and arguments, it achieves the same effect of passing arguments directly to `bwrap`, and thus can be used for a sandbox escape. The solution is to pass the `--` argument to `bwrap`, which makes it stop processing options. This has been supported since bubblewrap 0.3.0. All supported versions of Flatpak req...

CVSS3: 8.4
EPSS: Низкий
redhat логотип

CVE-2024-32462

больше 2 лет назад

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. Normally, the `--command` argument of `flatpak run` expects to be given a command to run in the specified Flatpak app, optionally along with some arguments. However it is possible to instead pass `bwrap` arguments to `--command=`, such as `--bind`. It's possible to pass an arbitrary `commandline` to the portal interface `org.freedesktop.portal.Background.RequestBackground` from within a Flatpak app. When this is converted into a `--command` and arguments, it achieves the same effect of passing arguments directly to `bwrap`, and thus can be used for a sandbox escape. The solution is to pass the `--` argument to `bwrap`, which makes it stop processing options. This has been supported since bubblewrap 0.3.0. All supported versions of Flatpak req...

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2024-32462

больше 2 лет назад

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. Normally, the `--command` argument of `flatpak run` expects to be given a command to run in the specified Flatpak app, optionally along with some arguments. However it is possible to instead pass `bwrap` arguments to `--command=`, such as `--bind`. It's possible to pass an arbitrary `commandline` to the portal interface `org.freedesktop.portal.Background.RequestBackground` from within a Flatpak app. When this is converted into a `--command` and arguments, it achieves the same effect of passing arguments directly to `bwrap`, and thus can be used for a sandbox escape. The solution is to pass the `--` argument to `bwrap`, which makes it stop processing options. This has been supported since bubblewrap 0.3.0. All supported versions of Flatpak requir

CVSS3: 8.4
EPSS: Низкий
debian логотип

CVE-2024-32462

больше 2 лет назад

Flatpak is a system for building, distributing, and running sandboxed ...

CVSS3: 8.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2067-1

больше 2 лет назад

Security update for xdg-desktop-portal

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1832-1

больше 2 лет назад

Security update for xdg-desktop-portal

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1831-1

больше 2 лет назад

Security update for xdg-desktop-portal

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1806-1

больше 2 лет назад

Security update for xdg-desktop-portal

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1803-1

больше 2 лет назад

Security update for xdg-desktop-portal

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1548-1

больше 2 лет назад

Security update for flatpak

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1547-1

больше 2 лет назад

Security update for flatpak

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1536-1

больше 2 лет назад

Security update for flatpak

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1535-1

больше 2 лет назад

Security update for flatpak

EPSS: Низкий
rocky логотип

RLSA-2024:3961

около 2 лет назад

Important: flatpak security update

EPSS: Низкий
rocky логотип

RLSA-2024:3959

около 2 лет назад

Important: flatpak security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-03113

Уязвимость интерфейса xdg-desktop-portal инструмента для управления приложениями и средами Flatpak, позволяющая нарушителю выйти из изолированной программной среды и получить доступ к файлам в базовой системе

CVSS3: 8.4
1%
Низкий
больше 2 лет назад
redos логотип
ROS-20240507-06

Уязвимость flatpak

CVSS3: 8.4
1%
Низкий
больше 2 лет назад
altlinux логотип
ALT-PU-2024-6956

ALT-PU-2024-6956: package `flatpak` update to version 1.14.6-alt1

CVSS3: 8.4
1%
Низкий
больше 2 лет назад
altlinux логотип
ALT-PU-2024-6954

ALT-PU-2024-6954: package `flatpak` update to version 1.14.6-alt1

CVSS3: 8.4
1%
Низкий
больше 2 лет назад
altlinux логотип
ALT-PU-2024-6822

ALT-PU-2024-6822: package `xdg-desktop-portal` update to version 1.18.4-alt1

CVSS3: 8.4
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-32462

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. Normally, the `--command` argument of `flatpak run` expects to be given a command to run in the specified Flatpak app, optionally along with some arguments. However it is possible to instead pass `bwrap` arguments to `--command=`, such as `--bind`. It's possible to pass an arbitrary `commandline` to the portal interface `org.freedesktop.portal.Background.RequestBackground` from within a Flatpak app. When this is converted into a `--command` and arguments, it achieves the same effect of passing arguments directly to `bwrap`, and thus can be used for a sandbox escape. The solution is to pass the `--` argument to `bwrap`, which makes it stop processing options. This has been supported since bubblewrap 0.3.0. All supported versions of Flatpak req...

CVSS3: 8.4
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32462

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. Normally, the `--command` argument of `flatpak run` expects to be given a command to run in the specified Flatpak app, optionally along with some arguments. However it is possible to instead pass `bwrap` arguments to `--command=`, such as `--bind`. It's possible to pass an arbitrary `commandline` to the portal interface `org.freedesktop.portal.Background.RequestBackground` from within a Flatpak app. When this is converted into a `--command` and arguments, it achieves the same effect of passing arguments directly to `bwrap`, and thus can be used for a sandbox escape. The solution is to pass the `--` argument to `bwrap`, which makes it stop processing options. This has been supported since bubblewrap 0.3.0. All supported versions of Flatpak req...

CVSS3: 8.4
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-32462

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. Normally, the `--command` argument of `flatpak run` expects to be given a command to run in the specified Flatpak app, optionally along with some arguments. However it is possible to instead pass `bwrap` arguments to `--command=`, such as `--bind`. It's possible to pass an arbitrary `commandline` to the portal interface `org.freedesktop.portal.Background.RequestBackground` from within a Flatpak app. When this is converted into a `--command` and arguments, it achieves the same effect of passing arguments directly to `bwrap`, and thus can be used for a sandbox escape. The solution is to pass the `--` argument to `bwrap`, which makes it stop processing options. This has been supported since bubblewrap 0.3.0. All supported versions of Flatpak requir

CVSS3: 8.4
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-32462

Flatpak is a system for building, distributing, and running sandboxed ...

CVSS3: 8.4
1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:2067-1

Security update for xdg-desktop-portal

1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1832-1

Security update for xdg-desktop-portal

1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1831-1

Security update for xdg-desktop-portal

1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1806-1

Security update for xdg-desktop-portal

1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1803-1

Security update for xdg-desktop-portal

1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1548-1

Security update for flatpak

1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1547-1

Security update for flatpak

1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1536-1

Security update for flatpak

1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1535-1

Security update for flatpak

1%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2024:3961

Important: flatpak security update

1%
Низкий
около 2 лет назад
rocky логотип
RLSA-2024:3959

Important: flatpak security update

1%
Низкий
около 2 лет назад

Уязвимостей на страницу