7.2
CVSSv2

CVE-2016-10117

Published: 13/04/2017 Updated: 19/04/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

firejail project firejail -

Vendor Advisories

A vulnerability has been found in firejail where any non-privileged user could mount a tmpfs over any location This could be exploited to, for example, mount over /etc to get a root shell ...