Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T14:55:35.375Z
Reserved: 2017-01-04T00:00:00
Link: CVE-2017-5180

No data.

Status : Modified
Published: 2017-02-09T18:59:00.127
Modified: 2024-11-21T03:27:12.900
Link: CVE-2017-5180

No data.