Sandbox Escape Vulnerability in Flatpak Proxy

Sandbox Escape Vulnerability in Flatpak Proxy

CVE-2018-6560 · MEDIUM Severity

AV:L/AC:L/AU:N/C:P/I:P/A:P

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.

Learn more about our Web Application Penetration Testing UK.