{"api_version":"1","generated_at":"2026-07-23T07:36:32+00:00","cve":"CVE-2017-5180","urls":{"html":"https://cve.report/CVE-2017-5180","api":"https://cve.report/api/cve/CVE-2017-5180.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-5180","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-5180"},"summary":{"title":"CVE-2017-5180","description":"Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2017-02-09 18:59:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"http://openwall.com/lists/oss-security/2017/01/04/2","name":"http://openwall.com/lists/oss-security/2017/01/04/2","refsource":"MISC","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: Firejail local root exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://firejail.wordpress.com/download-2/release-notes/","name":"https://firejail.wordpress.com/download-2/release-notes/","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"Release Notes | Firejail","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201701-62","name":"GLSA-201701-62","refsource":"GENTOO","tags":["Third Party Advisory"],"title":"Firejail: Multiple vulnerabilities (GLSA 201701-62) — Gentoo Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/95298","name":"95298","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Firejail CVE-2017-5180 Local Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-5180","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-5180","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"5180","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"firejail_project","cpe5":"firejail","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"-","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5180","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"firejail_project","cpe5":"firejail","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5180","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"firejail_project","cpe5":"firejail","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"-","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5180","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"firejail_project","cpe5":"firejail","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2017-5180","qid":"710391","title":"Gentoo Linux Firejail Multiple Vulnerabilities (GLSA 201701-62)"},{"cve":"CVE-2017-5180","qid":"710551","title":"Gentoo Linux Firejail Privilege escalation Vulnerability (GLSA 201702-03)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-5180","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"95298","refsource":"BID","url":"http://www.securityfocus.com/bid/95298"},{"name":"https://firejail.wordpress.com/download-2/release-notes/","refsource":"MISC","url":"https://firejail.wordpress.com/download-2/release-notes/"},{"name":"GLSA-201701-62","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201701-62"},{"name":"http://openwall.com/lists/oss-security/2017/01/04/2","refsource":"MISC","url":"http://openwall.com/lists/oss-security/2017/01/04/2"}]}},"nvd":{"publishedDate":"2017-02-09 18:59:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2,"impactScore":6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:firejail_project:firejail:*:*:*:*:-:*:*:*","versionEndExcluding":"0.9.44.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:firejail_project:firejail:*:*:*:*:lts:*:*:*","versionStartIncluding":"0.9.38","versionEndExcluding":"0.9.38.8","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"5180","Ordinal":"101686","Title":"CVE-2017-5180","CVE":"CVE-2017-5180","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"5180","Ordinal":"1","NoteData":"Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"5180","Ordinal":"2","NoteData":"2017-02-09","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"5180","Ordinal":"3","NoteData":"2017-03-23","Type":"Other","Title":"Modified"}]}}}