Ubuntu Security Update USN-4721-1: Flatpak vulnerability

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,929
Reaction score
75
Credits
-1,257
Simon McVittie discovered that flatpak-portal service allowed sandboxed applications to execute arbitrary code on the host system (a sandbox escape). A malicious user could create a Flatpak application that set environment variables, trusted by the Flatpak "run" command, and use it to execute arbitrary code outside the sandbox.

Continue reading...
 


Follow Linux.org

Members online


Top