CVE Vulnerabilities

CVE-2018-6560

Interpretation Conflict

Published: Feb 02, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.

Weakness

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B’s state.

Affected Software

NameVendorStart VersionEnd Version
FlatpakFlatpak*0.8.9 (excluding)
FlatpakFlatpak0.9.1 (including)0.9.99 (including)
FlatpakFlatpak0.10.0 (including)0.10.3 (excluding)
Red Hat Enterprise Linux 7RedHatflatpak-0:0.8.8-4.el7_5*
FlatpakUbuntuartful*
FlatpakUbuntuupstream*

References