CVE-2017-5180
Summary
| CVE | CVE-2017-5180 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-02-09 18:59:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - Re: Firejail local root exploit |
MISC |
openwall.com |
Mailing List, Third Party Advisory |
| Release Notes | Firejail |
MISC |
firejail.wordpress.com |
Release Notes, Vendor Advisory |
| Firejail: Multiple vulnerabilities (GLSA 201701-62) — Gentoo Security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Firejail CVE-2017-5180 Local Code Execution Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710391 Gentoo Linux Firejail Multiple Vulnerabilities (GLSA 201701-62)
- 710551 Gentoo Linux Firejail Privilege escalation Vulnerability (GLSA 201702-03)