4.6
CVSSv2

CVE-2018-6560

Published: 02/02/2018 Updated: 03/10/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 8.8 | Impact Score: 6 | Exploitability Score: 2
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In dbus-proxy/flatpak-proxy.c in Flatpak prior to 0.8.9, and 0.9.x and 0.10.x prior to 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.

Vulnerable Product Search on Vulmon Subscribe to Product

flatpak flatpak

redhat enterprise linux desktop 7.0

redhat enterprise linux server aus 7.6

redhat enterprise linux server eus 7.5

redhat enterprise linux server eus 7.6

redhat enterprise linux server tus 7.6

redhat enterprise linux server 7.0

redhat enterprise linux workstation 7.0

Vendor Advisories

Synopsis Moderate: flatpak security update Type/Severity Security Advisory: Moderate Topic An update for flatpak is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, wh ...
Debian Bug report logs - #888842 flatpak: CVE-2018-6560: D-Bus filtering can be bypassed by a crafted authentication handshake Package: flatpak; Maintainer for flatpak is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Source for flatpak is src:flatpak (PTS, buildd, popcon) Reported by: Simon McVitt ...
It was found that flatpak's D-Bus proxy did not properly filter the access to D-Bus during the authentication protocol A specially crafted flatpak application could use this flaw to bypass all restrictions imposed by flatpak and have full access to the D-BUS interface(CVE-2018-6560) ...
It was found that flatpak's D-Bus proxy did not properly filter the access to D-Bus during the authentication protocol A specially crafted flatpak application could use this flaw to bypass all restrictions imposed by flatpak and have full access to the D-BUS interface ...