PT-2020-5761 · Firejail+2 · Firejail+2
Tim Starling
·
Published
2020-08-06
·
Updated
2024-06-15
·
CVE-2020-17367
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Firejail versions 0.9.62 and earlier
Description:
The issue is related to the lack of measures to neutralize special elements in the
check output function from output.c in the Firejail isolated program environment. This may allow an attacker to gain access to confidential data, compromise their integrity, and cause a denial of service. The problem is also described as Firejail not honoring the --end-of-options indicator after the --output option, which may lead to command injection.Recommendations:
For Firejail versions 0.9.62 and earlier, as a temporary workaround, consider disabling the
check output function until a patch is available. Restrict access to the --output option to minimize the risk of command injection. Avoid using the --output option with untrusted input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.OS Command Injection
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Firejail
Suse