QID 198369

Date Published: 2021-05-25

QID 198369: Ubuntu Security Notification for Flatpak vulnerability (USN-4951-1)

It was discovered that Flatpak did not properly handle special tokens in desktop files.

An attacker could use this to specially craft a Flatpak application that could escape sandbox confinement

  • CVSS V3 rated as Critical - 8.2 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Refer to Ubuntu advisory: USN-4951-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198369

    Software Advisories
    Advisory ID Software Component Link
    USN-4951-1 Ubuntu Linux URL Logo usn.ubuntu.com/4951-1