CVE-2019-8308

Publication date 12 February 2019

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

8.2 · High

Score breakdown

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

Status

Package Ubuntu Release Status
flatpak 18.10 cosmic
Fixed 1.0.7-0ubuntu0.18.10.1
18.04 LTS bionic
Fixed 1.0.7-0ubuntu0.18.04.1
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release

Severity score breakdown

Parameter Value
Base score 8.2 · High
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction Required
Scope Changed
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H