2.1
CVSSv2

CVE-2016-10118

Published: 13/04/2017 Updated: 19/04/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /.

Vulnerable Product Search on Vulmon Subscribe to Product

firejail project firejail -

Vendor Advisories

Debian Bug report logs - #850160 firejail: CVE-2017-5180: local root exploit Package: firejail; Maintainer for firejail is Reiner Herrmann <reiner@reiner-hde>; Source for firejail is src:firejail (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Wed, 4 Jan 2017 14:09:02 UTC Severity: gra ...
A vulnerability has been found in firejail where any non-privileged user could truncate /etc/resolvconf to 0 bytes ...