SB2019050729 - Red Hat Enterprise Linux 7 update for flatpak
Published: May 7, 2019 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Security features bypass (CVE-ID: CVE-2019-10063)
CWE-ID: CWE-254 - Security Features
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a malicious application to bypass implemented security restrictions.
The vulnerability exists due to improper input validation. If Flatpak runs from a terminal emulator containing an interactive
shell, a malicious Flatpak app could inject input into the interactive
shell by using the TIOCSTI ioctl.
2) Input validation error (CVE-ID: CVE-2017-5226)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input. The non-privileged session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.
Remediation
Install update from vendor's website.