Security Advisory

CVE-2018-6560

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-02-02 14:00:00
Last updated 2024-08-05 06:10:10
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.