Vulnerability Name: | CVE-2017-9780 (CCN-127897) | ||||||||||||||||||||||||||||
Assigned: | 2017-06-12 | ||||||||||||||||||||||||||||
Published: | 2017-06-12 | ||||||||||||||||||||||||||||
Updated: | 2019-10-03 | ||||||||||||||||||||||||||||
Summary: | In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location. In the case of the "system helper" component, files deployed as part of the app are owned by root, so in the worst case they could be setuid root. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-732 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-9780 Source: DEBIAN Type: Third Party Advisory DSA-3895 Source: BID Type: Third Party Advisory, VDB Entry 99346 Source: CCN Type: BID-99346 Flatpak CVE-2017-9780 Local Privilege Escalation Vulnerability Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory https://bugs.debian.org/865413 Source: XF Type: UNKNOWN flatpak-cve20179780-priv-esc(127897) Source: CCN Type: flatpak GIT Repository handling suid/world-writable content #845 Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory https://github.com/flatpak/flatpak/issues/845 Source: CCN Type: WhiteSource Vulnerability Database CVE-2017-9780 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |