PT-2020-5761 · Firejail+2 · Firejail+2

Tim Starling

·

Published

2020-08-06

·

Updated

2024-06-15

·

CVE-2020-17367

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Firejail versions 0.9.62 and earlier
Description: The issue is related to the lack of measures to neutralize special elements in the check output function from output.c in the Firejail isolated program environment. This may allow an attacker to gain access to confidential data, compromise their integrity, and cause a denial of service. The problem is also described as Firejail not honoring the --end-of-options indicator after the --output option, which may lead to command injection.
Recommendations: For Firejail versions 0.9.62 and earlier, as a temporary workaround, consider disabling the check output function until a patch is available. Restrict access to the --output option to minimize the risk of command injection. Avoid using the --output option with untrusted input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2617
ALT-PU-2020-2653
ALT-PU-2020-3022
ALT-PU-2020-3055
BDU:2021-01718
CVE-2020-17367
DLA-2336-1
DSA-4742-1
DSA-4767-1
MGASA-2020-0328
OPENSUSE-SU-2020:1208-1
OPENSUSE-SU-2020_1208-1
OPENSUSE-SU-2021:0271-1
OPENSUSE-SU-2021_0271-1
OPENSUSE-SU-2024:10759-1

Affected Products

Alt Linux
Firejail
Suse