In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-18311 | In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T06:10:10.328Z
Reserved: 2018-02-02T00:00:00
Link: CVE-2018-6560
No data.
Status : Modified
Published: 2018-02-02T14:29:01.637
Modified: 2024-11-21T04:10:54.507
Link: CVE-2018-6560
OpenCVE Enrichment
No data.
EUVD