First published: Thu Apr 13 2017(Updated: )
Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netblue30 Firejail |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10117 has a medium severity level, indicating potential privilege escalation risks.
To fix CVE-2016-10117, it is recommended to update Firejail to the latest version that restricts access to --tmpfs.
Local users on systems using affected versions of Firejail are at risk from CVE-2016-10117.
CVE-2016-10117 allows local users to gain elevated privileges by improperly mounting over critical directories, like /etc.
A possible workaround for CVE-2016-10117 is to restrict user access to certain mount privileges in Firejail's configuration.