First published: Mon Sep 30 2024(Updated: )
It was discovered that Flatpak incorrectly handled certain persisted directories. An attacker could possibly use this issue to read and write files in locations it would not normally have access to. A patch was also needed to Bubblewrap in order to avoid race conditions caused by this fix.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/bubblewrap | <0.9.0-1ubuntu0.1 | 0.9.0-1ubuntu0.1 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/flatpak | <1.14.6-1ubuntu0.1 | 1.14.6-1ubuntu0.1 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/libflatpak0 | <1.14.6-1ubuntu0.1 | 1.14.6-1ubuntu0.1 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/bubblewrap | <0.6.1-1ubuntu0.1 | 0.6.1-1ubuntu0.1 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/flatpak | <1.12.7-1ubuntu0.1 | 1.12.7-1ubuntu0.1 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/libflatpak0 | <1.12.7-1ubuntu0.1 | 1.12.7-1ubuntu0.1 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/bubblewrap | <0.4.0-1ubuntu4.1 | 0.4.0-1ubuntu4.1 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/flatpak | <1.6.5-0ubuntu0.5 | 1.6.5-0ubuntu0.5 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/libflatpak0 | <1.6.5-0ubuntu0.5 | 1.6.5-0ubuntu0.5 |
Ubuntu Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.