Vulnerabilities > CVE-2017-5206 - Unspecified vulnerability in Firejail Project Firejail
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a seccomp-based sandbox protection mechanism via the --allow-debuggers argument.
Vulnerable Configurations
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-201701-62.NASL |
description | The remote host is affected by the vulnerability described in GLSA-201701-62 (Firejail: Multiple vulnerabilities) Multiple vulnerabilities have been discovered in Firejail. Please review the CVE identifiers referenced below for details. Impact : An attacker could possibly bypass sandbox protection, cause a Denial of Service condition, or escalate privileges. Workaround : There is no known workaround at this time. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 96748 |
published | 2017-01-25 |
reporter | This script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/96748 |
title | GLSA-201701-62 : Firejail: Multiple vulnerabilities |
code |
|
References
- http://www.openwall.com/lists/oss-security/2017/01/07/5
- http://www.openwall.com/lists/oss-security/2017/01/07/5
- http://www.securityfocus.com/bid/97120
- http://www.securityfocus.com/bid/97120
- https://blog.lizzie.io/linux-containers-in-500-loc.html#fn.51
- https://blog.lizzie.io/linux-containers-in-500-loc.html#fn.51
- https://firejail.wordpress.com/download-2/release-notes/
- https://firejail.wordpress.com/download-2/release-notes/
- https://github.com/netblue30/firejail/commit/6b8dba29d73257311564ee7f27b9b14758cc693e
- https://github.com/netblue30/firejail/commit/6b8dba29d73257311564ee7f27b9b14758cc693e
- https://security.gentoo.org/glsa/201701-62
- https://security.gentoo.org/glsa/201701-62