mirror of
https://github.com/netblue30/firejail.git
synced 2026-05-15 14:16:14 -06:00
[GH-ISSUE #1183] enhacement: fix these cve #811
Labels
No labels
LTS merge
LTS merge
bug
bug
converted-to-discussion
doc-todo
documentation
duplicate
enhancement
file-transfer
firecfg
firejail-in-firejail
firetools
graphics
help wanted
information_old
installation
invalid
modif
moved
needinfo
networking
notabug
notourbug
old-version
overlayfs
packaging
profile-request
pull-request
question
question_old
removal
runtime-permissions
sandbox-ipc
security
stale
wiki
wiki
wontfix
wordpress
workaround
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/firejail#811
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @nyancat18 on GitHub (Mar 31, 2017).
Original GitHub issue: https://github.com/netblue30/firejail/issues/1183
https://security.archlinux.org/package/firejail
@Fred-Barclay commented on GitHub (Mar 31, 2017):
Hi @triceratops1 I believe all of these have been fixed as of the latest release of firejail - version 0.9.44.10:
CVE-2016-10117 - was fixed in 0.9.38
CVE-2016-10118 - was fixed in 0.9.44.2 and 0.9.38.6
CVE-2016-10119 - was fixed in 0.9.38
CVE-2016-10120 - was fixed in 0.9.38
CVE-2016-10121 - was fixed in 0.9.38
CVE-2016-10122 - was fixed in 0.9.44.2
CVE-2016-10123 - was fixed in 0.9.38
CVE-2017-5180 - was fixed twice (there were two different ways to exploit this): originally in 0.9.38.8 and 0.9.44.4, and then later in 0.9.38.10 and 0.9.44.6.
CVE-2017-5206 - was fixed in 0.9.44.4
CVE-2017-5207 - was fixed in 0.9.44.4
(Side note: I was watching at the time, and CVE-2017-5207 was fixed within four hours of being reported.)
You can always check the current status of firejail, including bug fixes, from the release notes: https://firejail.wordpress.com/download-2/release-notes/)
If you want to check the status of the in-development code on GitHub, the release notes are here: https://github.com/netblue30/firejail/blob/master/RELNOTES
@netblue30 Can you check this for me and verify if I'm correct or not?
@netblue30 commented on GitHub (Mar 31, 2017):
Thanks @Fred-Barclay. It is missing CVE-2017-5940 (Arch people are also missing it athttps://security.archlinux.org/package/firejail).
It was fixed in 0.9.38.10 and 0.9.44.6. This is the second part for the incomplete fix in CVE-2017-5180. Most CVEs were published and numbers assigned after the release with the fix was out. The release notes in the package reflect the correct numbers after one more release. Anyway, I'll keep an up to date list here: https://firejail.wordpress.com/download-2/cve-status/