CVE-2018-6560: High severity Flatpak Flatpak vulnerability
A flaw was found in dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted. D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
References: https://github.com/flatpak/flatpak/releases/tag/0.8.9 https://github.com/flatpak/flatpak/releases/tag/0.10.3
Patch: https://github.com/flatpak/flatpak/commit/52346bf187b5a7f1c0fe9075b328b7ad6abe78f6
Other sources
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/flatpakto a version that resolves this vulnerability.Fixed in 0.8.9 - Upgrade
Upgrade
redhat/flatpakto a version that resolves this vulnerability.Fixed in 0.10.3 - Upgrade
Upgrade
flatpakto a version that resolves this vulnerability.Fixed in 0.8.9 - Upgrade
Upgrade
flatpakto a version that resolves this vulnerability.Fixed in 0.10.3
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6560?
The severity of CVE-2018-6560 is high with a CVSS score of 8.8.
How can this vulnerability be exploited?
Crafted D-Bus messages to the host can be used to break out of the sandbox.
Which versions of Flatpak are affected by this vulnerability?
Flatpak versions before 0.8.9, 0.9.x, and 0.10.x before 0.10.3 are affected.
How do I fix CVE-2018-6560?
Upgrade to Flatpak version 0.8.9 or later, 0.9.x or later, or 0.10.3 or later.
Where can I find more information about CVE-2018-6560?
You can find more information about CVE-2018-6560 at the following references: [link1](https://access.redhat.com/errata/RHSA-2018:2766), [link2](https://github.com/flatpak/flatpak/commit/52346bf187b5a7f1c0fe9075b328b7ad6abe78f6), [link3](https://github.com/flatpak/flatpak/releases/tag/0.10.3)