In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2018:2766 | Third Party Advisory |
https://github.com/flatpak/flatpak/commit/52346bf187b5a7f1c0fe9075b328b7ad6abe78f6 | Patch Vendor Advisory |
https://github.com/flatpak/flatpak/releases/tag/0.10.3 | Release Notes |
https://github.com/flatpak/flatpak/releases/tag/0.8.9 | Release Notes |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2018-02-02T14:00:00
Updated: 2018-09-26T09:57:01
Reserved: 2018-02-02T00:00:00
Link: CVE-2018-6560
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-02-02T14:29:01.637
Modified: 2019-10-03T00:03:26.223
Link: CVE-2018-6560
JSON object: View
Redhat Information
No data.
CWE