Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Fedora 27: 2018-bd651734da Critical Flatpak Sandbox Escape Fix

fedora
Calendar Grey February 6, 2018
Dist Fedora Esm H88
Ubuntu 20.04 snap upgrade resolves security vulnerabilities in system processes with essential patches and improved access controls.
This is a security fix release that fixes a sandbox escape in the flatpak dbus proxy

Summary

flatpak is a system for building, distributing and running sandboxed desktop

applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for

more information.

This is a security fix release that fixes a sandbox escape in the flatpak dbus

proxy. This issue was found by Gabriel Campana of The Google Security Team.

Major changes in 0.10.3 * Fix dbus proxy vulnerability in authentication phase

* Make permission handling ignore unknown permissions for forwards

compatibility * Removed incorrect error message in update --appdata when ther

was no updates * Fix handling of abort in the duplicate remote prompt * Fix

division by zero in progress calculation * Fix flatpak remote-info --show-metadata

su -c 'dnf upgrade flatpak' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 0.10.3
Release: 1.fc27
Summary: Application deployment framework for desktop apps

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here