Vulnerabilities > CVE-2017-5180 - Missing Authorization vulnerability in Firejail Project Firejail
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Exploit-Db
description | Firejail < 0.9.44.4 / < 0.9.38.8 LTS - Local Sandbox Escape. CVE-2017-5180. Local exploit for Linux platform |
id | EDB-ID:43359 |
last seen | 2017-12-19 |
modified | 2017-01-04 |
published | 2017-01-04 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/43359/ |
title | Firejail < 0.9.44.4 / < 0.9.38.8 LTS - Local Sandbox Escape |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-201701-62.NASL |
description | The remote host is affected by the vulnerability described in GLSA-201701-62 (Firejail: Multiple vulnerabilities) Multiple vulnerabilities have been discovered in Firejail. Please review the CVE identifiers referenced below for details. Impact : An attacker could possibly bypass sandbox protection, cause a Denial of Service condition, or escalate privileges. Workaround : There is no known workaround at this time. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 96748 |
published | 2017-01-25 |
reporter | This script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/96748 |
title | GLSA-201701-62 : Firejail: Multiple vulnerabilities |
code |
|
References
- http://openwall.com/lists/oss-security/2017/01/04/2
- http://openwall.com/lists/oss-security/2017/01/04/2
- http://www.securityfocus.com/bid/95298
- http://www.securityfocus.com/bid/95298
- https://firejail.wordpress.com/download-2/release-notes/
- https://firejail.wordpress.com/download-2/release-notes/
- https://security.gentoo.org/glsa/201701-62
- https://security.gentoo.org/glsa/201701-62