~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2017-5180

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2017-5180
2
 
PublicDate: 2017-02-09
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5180
5
 
 http://www.openwall.com/lists/oss-security/2017/01/04/1
6
 
 https://github.com/netblue30/firejail/issues/1020
7
 
 http://www.openwall.com/lists/oss-security/2017/01/05/1
8
 
Description:
9
 
 Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not
10
 
 consider the .Xauthority case during its attempt to prevent accessing user
11
 
 files with an euid of zero, which allows local users to conduct
12
 
 sandbox-escape attacks via vectors involving a symlink and the --private
13
 
 option.
14
 
Ubuntu-Description:
15
 
Notes:
16
 
Bugs:
17
 
 https://bugs.launchpad.net/ubuntu/xenial/+source/firejail/+bug/1655136
18
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850160
19
 
Priority: medium
20
 
Discovered-by: Sebastian Krahmer
21
 
Assigned-to:
22
 
 
23
 
Patches_firejail:
24
 
upstream_firejail: released (0.9.44.2-2)
25
 
precise_firejail: DNE
26
 
precise/esm_firejail: DNE
27
 
trusty_firejail: DNE
28
 
vivid/stable-phone-overlay_firejail: DNE
29
 
vivid/ubuntu-core_firejail: DNE
30
 
xenial_firejail: released (0.9.38-1ubuntu0.1)
31
 
yakkety_firejail: ignored (reached end-of-life)
32
 
zesty_firejail: not-affected (0.9.44.8-1)
33
 
devel_firejail: not-affected (0.9.44.8-1)