Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 31: Firejail 2020-80a6d7e7e0 Moderate: Command Injection Risk

fedora
Calendar Grey August 26, 2020
Dist Fedora Esm H88
Enhancement notice for firejail regarding address command injection vulnerabilities, improving overall security measures in Fedora 31. Execute with dnf upgrade.
Rebase to version 0.9.62.4 ---- Rebase to version 0.9.62.2

Summary

Firejail is a SUID sandbox program that reduces the risk of security

breaches by restricting the running environment of untrusted applications

using Linux namespaces. It includes a sandbox profile for Mozilla Firefox.

Rebase to version 0.9.62.4 ---- Rebase to version 0.9.62.2

* Tue Aug 18 2020 Ondrej Dubaj - 0.9.62.4-1

- Rebase to version 0.9.62.4

* Wed Aug 12 2020 Ondrej Dubaj - 0.9.62.2-1

- Rebase to version 0.9.62.2

[ 1 ] Bug #1868014 - firejail-0.9.62.2 is available

https://bugzilla.redhat.com/show_bug.cgi?id=1868014

[ 2 ] Bug #1868336 - CVE-2020-17367 firejail: end-of-options indicator after the --output option not respected which may lead to command injection [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1868336

[ 3 ] Bug #1868338 - CVE-2020-17368 firejail: mishandling shell metacharacters during use of the --output may lead to command injection [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1868338

[ 4 ] Bug #1869381 - firejail-0.9.62.4 is available

https://bugzilla.redhat.com/show_bug.cgi?id=1869381

su -c 'dnf upgrade --advisory FEDORA-2020-80a6d7e7e0' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 31
Version: 0.9.62.4
Release: 1.fc31
Summary: Linux namespaces sandbox program

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here