cbcvebase.
CVE-2019-8308
published 2019-02-12

CVE-2019-8308: Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side…

high8.2CVSS 3.0
AVLACLPRLUIRSCCHIHAH
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianflatpak< flatpak 1.2.3-1 (bookworm)flatpak 1.2.3-1 (bookworm)
flatpakflatpak< 1.0.71.0.7
flatpakflatpak>= 0 < 1.2.3-11.2.3-1
flatpakflatpak>= 0 < 1.2.3-11.2.3-1
flatpakflatpak>= 0 < 1.2.3-11.2.3-1
flatpakflatpak>= 0 < 1.2.3-11.2.3-1
flatpakflatpak1.1.0 – 1.1.3
flatpakflatpak1.2.0 – 1.2.3
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.08.2HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
osv8.2HIGH