PT-2017-19183 · Flatpak · Flatpak

Cgwalters

·

Publicado

2017-06-21

·

Atualizado

2019-10-03

·

CVE-2017-9780

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flatpak versions prior to 0.8.7
Description A third-party app repository could include malicious apps with files that have inappropriate permissions, such as setuid or world-writable. These files are deployed with the specified permissions, allowing a local attacker to run the setuid executable or write to the world-writable location. In the case of the "system helper" component, files deployed as part of the app are owned by root, potentially leading to setuid root in the worst-case scenario.
Recommendations For versions prior to 0.8.7, update to version 0.8.7 or later to resolve the issue. As a temporary workaround, consider restricting the installation of apps from third-party repositories to minimize the risk of exploitation.

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-9780
DSA-3895-1

Produtos afetados

Flatpak