CVE-2018-6560
published 2018-02-02CVE-2018-6560: In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the…
PriorityP338high8.8CVSS 3.0
AVLACLPRLUINSCCHIHAH
EPSS
0.41%
33.8th percentile
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | flatpak | < flatpak 0.10.3-1 (bookworm) | flatpak 0.10.3-1 (bookworm) |
| flatpak | flatpak | < 0.8.9 | 0.8.9 |
| flatpak | flatpak | >= 0 < 0.10.3-1 | 0.10.3-1 |
| flatpak | flatpak | >= 0 < 0.10.3-1 | 0.10.3-1 |
| flatpak | flatpak | >= 0 < 0.10.3-1 | 0.10.3-1 |
| flatpak | flatpak | >= 0 < 0.10.3-1 | 0.10.3-1 |
| flatpak | flatpak | >= 0.10.0 < 0.10.3 | 0.10.3 |
| flatpak | flatpak | 0.9.1 – 0.9.99 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flatpak: sandbox escape in D-Bus filtering by a crafted authentication handshake
vendor_redhat·2018-01-29·CVSS 8.8
CVE-2018-6560 [HIGH] CWE-270 flatpak: sandbox escape in D-Bus filtering by a crafted authentication handshake
flatpak: sandbox escape in D-Bus filtering by a crafted authentication handshake
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
It was found that flatpak's D-Bus proxy did not properly filter the access to D-Bus during the authentication protocol. A specially crafted flatpak application could use this flaw to bypass all restrictions imposed by flatpak and have full access to the D-BUS interface.
Package: flatpak (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-6560: flatpak - In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x befo...
vendor_debian·2018·CVSS 8.8
CVE-2018-6560 [HIGH] CVE-2018-6560: flatpak - In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x befo...
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
Scope: local
bookworm: resolved (fixed in 0.10.3-1)
bullseye: resolved (fixed in 0.10.3-1)
forky: resolved (fixed in 0.10.3-1)
sid: resolved (fixed in 0.10.3-1)
trixie: resolved (fixed in 0.10.3-1)
GHSA
GHSA-5xcx-r88v-8v7g: In dbus-proxy/flatpak-proxy
ghsa_unreviewed·2022-05-13
CVE-2018-6560 [HIGH] CWE-436 GHSA-5xcx-r88v-8v7g: In dbus-proxy/flatpak-proxy
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
OSV
CVE-2018-6560: In dbus-proxy/flatpak-proxy
osv·2018-02-02·CVSS 8.8
CVE-2018-6560 [HIGH] CVE-2018-6560: In dbus-proxy/flatpak-proxy
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2018:2766https://github.com/flatpak/flatpak/commit/52346bf187b5a7f1c0fe9075b328b7ad6abe78f6https://github.com/flatpak/flatpak/releases/tag/0.10.3https://github.com/flatpak/flatpak/releases/tag/0.8.9https://access.redhat.com/errata/RHSA-2018:2766https://github.com/flatpak/flatpak/commit/52346bf187b5a7f1c0fe9075b328b7ad6abe78f6https://github.com/flatpak/flatpak/releases/tag/0.10.3https://github.com/flatpak/flatpak/releases/tag/0.8.9
2018-02-02
Published