Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-02-09T18:00:00
Updated: 2024-08-05T14:55:35.375Z
Reserved: 2017-01-04T00:00:00
Link: CVE-2017-5180
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-02-09T18:59:00.127
Modified: 2024-11-21T03:27:12.900
Link: CVE-2017-5180
Redhat
No data.