[GH-ISSUE #1183] enhacement: fix these cve #811

Closed
opened 2026-05-05 06:53:31 -06:00 by gitea-mirror · 2 comments
Owner

Originally created by @nyancat18 on GitHub (Mar 31, 2017).
Original GitHub issue: https://github.com/netblue30/firejail/issues/1183

https://security.archlinux.org/package/firejail

Originally created by @nyancat18 on GitHub (Mar 31, 2017). Original GitHub issue: https://github.com/netblue30/firejail/issues/1183 https://security.archlinux.org/package/firejail
gitea-mirror 2026-05-05 06:53:31 -06:00
Author
Owner

@Fred-Barclay commented on GitHub (Mar 31, 2017):

Hi @triceratops1 I believe all of these have been fixed as of the latest release of firejail - version 0.9.44.10:

CVE-2016-10117 - was fixed in 0.9.38
CVE-2016-10118 - was fixed in 0.9.44.2 and 0.9.38.6
CVE-2016-10119 - was fixed in 0.9.38
CVE-2016-10120 - was fixed in 0.9.38
CVE-2016-10121 - was fixed in 0.9.38
CVE-2016-10122 - was fixed in 0.9.44.2
CVE-2016-10123 - was fixed in 0.9.38
CVE-2017-5180 - was fixed twice (there were two different ways to exploit this): originally in 0.9.38.8 and 0.9.44.4, and then later in 0.9.38.10 and 0.9.44.6.
CVE-2017-5206 - was fixed in 0.9.44.4
CVE-2017-5207 - was fixed in 0.9.44.4

(Side note: I was watching at the time, and CVE-2017-5207 was fixed within four hours of being reported.)

You can always check the current status of firejail, including bug fixes, from the release notes: https://firejail.wordpress.com/download-2/release-notes/)
If you want to check the status of the in-development code on GitHub, the release notes are here: https://github.com/netblue30/firejail/blob/master/RELNOTES

@netblue30 Can you check this for me and verify if I'm correct or not?

<!-- gh-comment-id:290732746 --> @Fred-Barclay commented on GitHub (Mar 31, 2017): Hi @triceratops1 I believe all of these have been fixed as of the latest release of firejail - version 0.9.44.10: CVE-2016-10117 - was fixed in 0.9.38 CVE-2016-10118 - was fixed in 0.9.44.2 and 0.9.38.6 CVE-2016-10119 - was fixed in 0.9.38 CVE-2016-10120 - was fixed in 0.9.38 CVE-2016-10121 - was fixed in 0.9.38 CVE-2016-10122 - was fixed in 0.9.44.2 CVE-2016-10123 - was fixed in 0.9.38 CVE-2017-5180 - was fixed twice (there were two different ways to exploit this): originally in 0.9.38.8 and 0.9.44.4, and then later in 0.9.38.10 and 0.9.44.6. CVE-2017-5206 - was fixed in 0.9.44.4 CVE-2017-5207 - was fixed in 0.9.44.4 (Side note: I was watching at the time, and CVE-2017-5207 was fixed within four hours of being reported.) You can always check the current status of firejail, including bug fixes, from the release notes: https://firejail.wordpress.com/download-2/release-notes/) If you want to check the status of the in-development code on GitHub, the release notes are here: https://github.com/netblue30/firejail/blob/master/RELNOTES @netblue30 Can you check this for me and verify if I'm correct or not?
Author
Owner

@netblue30 commented on GitHub (Mar 31, 2017):

Thanks @Fred-Barclay. It is missing CVE-2017-5940 (Arch people are also missing it athttps://security.archlinux.org/package/firejail).

It was fixed in 0.9.38.10 and 0.9.44.6. This is the second part for the incomplete fix in CVE-2017-5180. Most CVEs were published and numbers assigned after the release with the fix was out. The release notes in the package reflect the correct numbers after one more release. Anyway, I'll keep an up to date list here: https://firejail.wordpress.com/download-2/cve-status/

<!-- gh-comment-id:290774294 --> @netblue30 commented on GitHub (Mar 31, 2017): Thanks @Fred-Barclay. It is missing CVE-2017-5940 (Arch people are also missing it athttps://security.archlinux.org/package/firejail). It was fixed in 0.9.38.10 and 0.9.44.6. This is the second part for the incomplete fix in CVE-2017-5180. Most CVEs were published and numbers assigned after the release with the fix was out. The release notes in the package reflect the correct numbers after one more release. Anyway, I'll keep an up to date list here: https://firejail.wordpress.com/download-2/cve-status/
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: github-starred/firejail#811
No description provided.