In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HFlatpak
APPFlatpak< 0.8.90.9.1 – 0.9.990.10.0 – 0.10.3 (excl.)Red Hat Enterprise Linux Desktop
OSRedhat7.0Red Hat Enterprise Linux Server
OSRedhat7.0Red Hat Enterprise Linux Server Aus
OSRedhat7.6Red Hat Enterprise Linux Server Eus
OSRedhat7.57.6Red Hat Enterprise Linux Server Tus
OSRedhat7.6Red Hat Enterprise Linux Workstation
OSRedhat7.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2019-5544CRITICAL9.8⚠ KEVPL ✓same product
Krytyczny heap overwrite w OpenSLP dla VMware ESXi i Horizon DaaS
CVE-2016-4171CRITICAL9.8⚠ KEVPL ✓same product
RCE w Adobe Flash Player 21.0.0.242 i wcześniejszych — aktywnie exploitowany
CVE-2016-4117CRITICAL9.8⚠ KEVPL ✓same product
Adobe Flash Player — RCE umożliwiający wykonanie dowolnego kodu
CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX