CVE-2016-9016Improper Access Control in Project Firejail

Severity
8.8HIGHNVD
EPSS
0.1%
top 66.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 19
Latest updateMay 17

Description

Firejail 0.9.38.4 allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages2 packages

Debianfirejail_project/firejail< 0.9.44-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5wqv-pw8v-69qc: Firejail 02022-05-17
OSV
CVE-2016-9016: Firejail 02017-01-19
CVEList
CVE-2016-9016: Firejail 02017-01-19

📋Vendor Advisories

1
Debian
CVE-2016-9016: firejail - Firejail 0.9.38.4 allows local users to execute arbitrary commands outside of th...2016
CVE-2016-9016 — Improper Access Control | cvebase