漏洞信息详情
Flatpak 注入漏洞
漏洞简介
Flatpak是一套用于Linux桌面应用计算机环境的应用程序虚拟化系统。
Flatpak 存在安全漏洞,攻击者可利用该漏洞访问应用程序权限通常不允许的文件。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/flatpak/flatpak/commit/eb7946bb6248923d8c90fe9b84425fef97ae580d
参考网址
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/WXNVFOIB6ZP4DGOVKAM25T6OIEP3YLGV/
来源:MISC
链接:https://github.com/flatpak/flatpak/commit/a7401e638bf0c03102039e216ab1081922f140ae
来源:MISC
链接:https://github.com/flatpak/flatpak/pull/4156
来源:MISC
链接:https://github.com/flatpak/flatpak/commit/eb7946bb6248923d8c90fe9b84425fef97ae580d
来源:CONFIRM
链接:https://github.com/flatpak/flatpak/security/advisories/GHSA-xgh4-387p-hqpp
来源:DEBIAN
链接:https://www.debian.org/security/2021/dsa-4868
来源:MISC
链接:https://github.com/flatpak/flatpak/commit/8279c5818425b6812523e3805bbe242fb6a5d961
来源:MISC
链接:https://github.com/flatpak/flatpak/releases/tag/1.10.2
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/2MXXLXC2DPJ45HSMTI5MZYHMYEGQN6AA/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1631
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162551/Ubuntu-Security-Notice-USN-4951-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0892
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1079
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162096/Red-Hat-Security-Advisory-2021-1068-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162009/Red-Hat-Security-Advisory-2021-1002-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1149
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-21381
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021080916
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Flatpak-read-write-access-via-File-Forwarding-34841
受影响实体
暂无
补丁
- Flatpak 注入漏洞的修复措施<!--2021-3-11-->
还没有评论,来说两句吧...