firejail-project
Operating Systemsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting firejail-project.
- CVE-2022-31214A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container that is accepted by the Firejail setuid-root program as a join target, a loca...7.8
- CVE-2021-26910Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.7.8
- CVE-2020-17368Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.9.8
- CVE-2020-17367Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.7.8
- CVE-2019-12589In Firejail before 0.9.60, seccomp filters are writable inside the jail, leading to a lack of intended seccomp restrictions for a process that is joined to the jail after a filter has been modified...8.8
- CVE-2019-12499Firejail before 0.9.60 allows truncation (resizing to length 0) of the firejail binary on the host by running exploit code inside a firejail sandbox and having the sandbox terminated. To succeed, c...8.1
- CVE-2016-10123Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.7.8
- CVE-2016-10121Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges.7.8
- CVE-2016-10122Firejail does not properly clean environment variables, which allows local users to gain privileges.7.8
- CVE-2016-10120Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges.7.8
- CVE-2016-10117Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.7.8
- CVE-2016-10119Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges.7.8
- CVE-2016-10118Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /.3.3
- CVE-2017-5206Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a seccomp-based sandbox protection mechanism via the --allow-debuggers argument.9.0
- CVE-2017-5207Firejail before 0.9.44.4, when running a bandwidth command, allows local users to gain root privileges via the --shell argument.7.8