CVE-2016-10122Project Firejail vulnerability

CWE-2645 documents5 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 87.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 13
Latest updateMay 17

Description

Firejail does not properly clean environment variables, which allows local users to gain privileges.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

Debianfirejail_project/firejail< 0.9.44.2-1+3

🔴Vulnerability Details

3
GHSA
GHSA-pqfv-45vx-4988: Firejail does not properly clean environment variables, which allows local users to gain privileges2022-05-17
CVEList
CVE-2016-10122: Firejail does not properly clean environment variables, which allows local users to gain privileges2017-04-13
OSV
CVE-2016-10122: Firejail does not properly clean environment variables, which allows local users to gain privileges2017-04-13

📋Vendor Advisories

1
Debian
CVE-2016-10122: firejail - Firejail does not properly clean environment variables, which allows local users...2016
CVE-2016-10122 — Project Firejail vulnerability | cvebase